---
schema_version: '1.0'
id: security-20260705-a3eae5
url: https://osv.dev/vulnerability/DEBIAN-CVE-2025-23419
url_hash: a3eae5870d68b6797c4a3af3d1aa3f1fa80db10d3ad43a02d887aa482a5d97a1
canonical_url: https://osv.dev/vulnerability/DEBIAN-CVE-2025-23419
source: osv:debian
category: security/os
category_raw: cve/os
region: null
tags:
- cve
- DEBIAN-CVE-2025-23419
- severity:CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- nginx
- Debian
lang: en
published_at: '2025-02-05T18:15:33Z'
fetched_at: '2026-07-05T15:34:33Z'
updated_at: '2026-07-05T15:34:52Z'
status: published
content_hash: 0a241b85e9dfd37e09e55f3b1c45ba045486fa65e7cca7a24ebb0f6f5bfa884a
license_note: full
summary: When multiple server blocks are configured to share the same IP address and
  port, an attacker can use session resumption to bypass client certificate authentication
  requirements on these servers. This vulnerability arises when  TLS Session Tickets
  https://nginx.org/en/docs/http/n
summary_source: rss
summary_en: When multiple server blocks are configured to share the same IP address
  and port, an attacker can use session resumption to bypass client certificate authentication
  requirements on these servers. This vulnerability arises when  TLS Session Tickets
  https://nginx.org/en/docs/http/n
entities: []
key_facts: []
related: []
related_auto: []
title: DEBIAN-CVE-2025-23419 — nginx
---

# DEBIAN-CVE-2025-23419 — nginx

## TL;DR
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/n

## Key Points
- cve / DEBIAN-CVE-2025-23419 / severity:CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X / nginx / Debian

## Details
**Severity:** CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
**Advisory:** DEBIAN-CVE-2025-23419

**Affected (your watchlist):**
- `Debian:nginx` 1.22.1-9+deb12u1 → no fixed version listed [proxmox]

**Details:**
When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when  TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key  are used and/or the  SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache  are used in the default server and the default server is performing client certificate authentication.    Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

**References:**
- https://security-tracker.debian.org/tracker/CVE-2025-23419

_Data: OSV.dev (upstream: debian) — https://osv.dev/vulnerability/DEBIAN-CVE-2025-23419_

## Source
元記事: [DEBIAN-CVE-2025-23419 — nginx](https://osv.dev/vulnerability/DEBIAN-CVE-2025-23419) — published 2025-02-05T18:15:33Z
