CVE-2025-23048-POC. Apache HTTP Server versions 2.4.35 – 2.4.63 are vulnerable to a client certificate authentication bypass when TLS 1.3 session resumption is used across virtual hosts with different `SSLCACertificateFile` directives.

github.com/absholi7ly/CVE-2025-23048-POC

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.