CVE-2025-23419

EUVD-2025-3168
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.  

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
Affected Products (NVD)
VendorProductVersion
f5nginx
1.11.4 ≤
𝑥
< 1.26.3
f5nginx
1.27.0 ≤
𝑥
< 1.27.4
f5nginx_plus
r28 ≤
𝑥
< r32
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nginx
suse enterprise sap 15 SP6
1.21.5-150600.10.12.1
fixed
suse enterprise sap 15 SP7
1.21.5-150600.10.12.1
fixed
suse enterprise server 15 SP4
1.21.5-150400.3.12.1
fixed
suse enterprise server 15 SP6
1.21.5-150600.10.12.1
fixed
suse enterprise server 15 SP7
1.21.5-150600.10.12.1
fixed
nginx-source
suse enterprise sap 15 SP6
1.21.5-150600.10.12.1
fixed
suse enterprise sap 15 SP7
1.21.5-150600.10.12.1
fixed
suse enterprise server 15 SP4
1.21.5-150400.3.12.1
fixed
suse enterprise server 15 SP6
1.21.5-150600.10.12.1
fixed
suse enterprise server 15 SP7
1.21.5-150600.10.12.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
nginx
RHEL 9
2:1.20.1-22.el9
fixed
nginx-all-modules
RHEL 9
2:1.20.1-22.el9
fixed
nginx-core
RHEL 9
2:1.20.1-22.el9
fixed
nginx-filesystem
RHEL 9
2:1.20.1-22.el9
fixed
nginx-mod-devel
RHEL 9
2:1.20.1-22.el9
fixed
nginx-mod-http-image-filter
RHEL 9
2:1.20.1-22.el9
fixed
nginx-mod-http-perl
RHEL 9
2:1.20.1-22.el9
fixed
nginx-mod-http-xslt-filter
RHEL 9
2:1.20.1-22.el9
fixed
nginx-mod-mail
RHEL 9
2:1.20.1-22.el9
fixed
nginx-mod-stream
RHEL 9
2:1.20.1-22.el9
fixed