When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Conclusion & alert: CVE-2025-23419 is rated Moderate Risk (49.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.56%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 2.86% | 2.56% | -0.30% |
| 2 | 2026-05-05 | 1.16% | 2.86% | +1.69% |
| 3 | 2026-04-27 | — | 1.16% | — |
Full EPSS history (34 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 4.0 | MEDIUM |
|
— | — | [email protected] |
| 4.3 | 3.1 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-23419: 1 source package rows (nginx); 60 state rows across 5 repos (3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 4, open 56. | https://security.alpinelinux.org/vuln/CVE-2025-23419 |
debian
|
not yet assigned | CVE-2025-23419 not yet assigned priority: Debian including 1 source packages (nginx), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-23419 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-23419 |
suse
|
medium | CVE-2025-23419 severity moderate: SUSE including 18 source package names (1.1.0-1.1:nginx-1.21.5-150600.10.12.1, 1.21.5-2.51:nginx-1.21.5-150600.10.12.1, …), 22 product×package rows across 8 product lines (Container private-registry/harbor-nginx, Container private-registry/harbor-portal, … (8 product lines)): Fixed 22. | https://www.suse.com/security/cve/CVE-2025-23419/ |
ubuntu
|
medium | CVE-2025-23419 medium priority: Ubuntu including 1 source packages (nginx), 10 status rows across 10 suites (bionic, focal, jammy, noble, oracular, plucky, questing, trusty, upstream, xenial): released 5, needs-triage 3, not-affected 2. | https://ubuntu.com/security/CVE-2025-23419 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| f5 | nginx | >= 1.11.4, < 1.26.3 | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* |
| f5 | nginx | >= 1.27.0, < 1.27.4 | cpe:2.3:a:f5:nginx:*:*:*:*:*:*:*:* |
| f5 | nginx_plus | >= r28, < r32 | cpe:2.3:a:f5:nginx_plus:*:*:*:*:*:*:*:* |
| f5 | nginx_plus | r32 | cpe:2.3:a:f5:nginx_plus:r32:-:*:*:*:*:*:* |
| f5 | nginx_plus | r32 | cpe:2.3:a:f5:nginx_plus:r32:p1:*:*:*:*:*:* |
| f5 | nginx_plus | r33 | cpe:2.3:a:f5:nginx_plus:r33:-:*:*:*:*:*:* |
| f5 | nginx_plus | r33 | cpe:2.3:a:f5:nginx_plus:r33:p1:*:*:*:*:*:* |
| debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://my.f5.com/manage/s/article/K000149173 | Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2025/02/05/8 | Mailing List Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2025/03/msg00017.html | Issue Tracking Third Party Advisory |