CVE-2025-23419: TLS Session Resumption Vulnerability

Published Feb 5, 2025
·
Updated

Last updated 24 February 2025

Other sources

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngxhttpsslmodule.html#sslsessionticketkey are used and/or the SSL session cache https://nginx.org/en/docs/http/ngxhttpsslmodule.html#sslsessioncache are used in the default server and the default server is performing client certificate authentication.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

NVD

When name-based virtual hosts are configured to share the same IP address and port combination, with TLS 1.3 and OpenSSL, a previously authenticated attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS session tickets are used and/or the SSL session cache is used in the default virtual server and the default virtual server is performing client certificate authentication. This issue affects both the NGINX http and NGINX stream modules.

F5

Affected Software

14 affected componentsFixes available
debian/nginx<=1.18.0-6.1+deb11u3
1.18.0-6.1+deb11u41.22.1-9+deb12u11.26.3-2
F5 NGINX Plus=28
33
F5 NGINX Open Source>=1.11.4<=1.27.3
1.27.431.26.33
F5 Nginx>=1.11.4<1.26.3
F5 Nginx>=1.27.0<1.27.4
F5 NGINX Plus>=r28<r32
F5 NGINX Plus=r32
F5 NGINX Plus=r32-p1
F5 NGINX Plus=r33
F5 NGINX Plus=r33-p1
Debian Debian Linux=11.0
Microsoft cbl2 nginx 1.22.1-13<1.22.1-13
1.22.1-13
Microsoft azl3 nginx 1.25.4-3<1.25.4-3
1.25.4-3
Microsoft azl3 nginx 1.25.4-4<1.25.4-3
1.25.4-3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade debian/nginx to a version that resolves this vulnerability.

    Fixed in 1.18.0-6.1+deb11u4Fixed in 1.22.1-9+deb12u1Fixed in 1.26.3-2
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 33
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.27.431.26.33
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.22.1-13
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.25.4-3
  6. Configuration

    If the default server/default virtual server performs client certificate authentication, disable/avoid using TLS Session Tickets (ssl_session_ticket_key) and the SSL session cache (ssl_session_cache).

    nginx http (ngx_http_ssl_module) and nginx stream ssl_session_ticket_key (TLS Session Tickets) / ssl_session_cache (SSL session cache) usage on the default server (default virtual server) = Do not use TLS Session Tickets and/or SSL session cache in the default server (default virtual server) when client certificate authentication is configured
  7. Configuration

    Do not configure multiple server blocks or name-based virtual hosts that share the same IP address and port combination when TLS 1.3 with OpenSSL session resumption can reach client certificate authentication bypass; separate them to prevent cross-server session resumption bypass.

    nginx (virtual host configuration) shared IP:port for server blocks and session resumption behavior = Ensure separate IP address/port (or avoid sharing) when client certificate authentication is enabled

Event History

Feb 5, 2025
Advisory Published
via F5·02:13 PM
Data Sourced
via F5·02:13 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
Affected Software
Feb 16, 2025
Data Sourced
via Microsoft·08:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:00 AM
Affected Software
Updated
via Microsoft·08:00 AM
DescriptionSeverity
Feb 28, 2025
Data Sourced
via Ubuntu·02:56 PM
RemedyDescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-23419?

CVE-2025-23419 is considered a high severity vulnerability due to its potential to bypass client certificate authentication.

2

How do I fix CVE-2025-23419?

To mitigate CVE-2025-23419, update NGINX Plus to version 28 or NGINX Open Source to a version beyond 1.27.3.

3

What type of attack does CVE-2025-23419 enable?

CVE-2025-23419 allows an authenticated attacker to bypass client certificate authentication using session resumption.

4

Which software is affected by CVE-2025-23419?

CVE-2025-23419 affects NGINX Plus version 28 and NGINX Open Source versions between 1.11.4 and 1.27.3.

5

What configurations are impacted by CVE-2025-23419?

CVE-2025-23419 impacts servers with name-based virtual hosts sharing the same IP address and port using TLS 1.3.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203