CVE-2025-23419Patch(debian / debian_linux)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch debian debian_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When multiple server blocks are configured to share the same IP address and port, an attacker can use session resumption to bypass client certificate authentication requirements on these servers. This vulnerability arises when TLS Session Tickets https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_ticket_key are used and/or the SSL session cache https://nginx.org/en/docs/http/ngx_http_ssl_module.html#ssl_session_cache are used in the default server and the default server is performing client certificate authentication.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • nginx
  • nginx_plus

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-14); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
debian_linuxnginxnginx_plus

3 versions affected across 3 products

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-14: 2Mentions · 2026-07-12: 1Patch / Workaround · 2026-05-14: 205-1407-12
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-142
Patch2
2026-07-121
General1
Full discourse3 posts
  • NadeshikoManju@ゆるキャン△ SEASON4 2027 放送予定@Manjusaka_Lee
    Patch

    Kubernetes 官方的 Ingress Nginx Controller bundle 的 Nginx 版本是 1.27.1 基本可以自己无缝 bundle 到 1.31.0 唯一需要注意的是中间有个 CVE-2025-23419 的 patch 可以移除(因为 Nginx 有自己的修复),剩下的基本无缝升级 老老实实自己的打镜像吧

    Post summary

    The post notes that upgrading the Ingress Nginx Controller to nginx 1.31.0 is feasible after removing the patch for CVE-2025-23419, as nginx has its own fix.

    0102156.2K
    37.3K followersView on X
  • Navneet@navneet_rabdiya
    Patch

    @hetmehtaa CVE-2025-23419 affects the ngx_http_mp4_module specifically - so if you're not serving MP4s via that module, your actual exposure is lower than the headline suggests. Still patch, but worth checking if the module is even compiled in before treating it as P0.

    Post summary

    The tweet notes that CVE-2025-23419 impacts the ngx_http_mp4_module, suggests risk is lower if MP4 serving isn’t used, and advises applying the available patch.

    100201.4K
    558 followersView on X
  • Hugo Angulo@thermotronica
    General

    CVE-2023-44487 https://nvd.nist.gov/vuln/detail/cve-2023-44487#match-24040570 CVE-2025-23419 https://nvd.nist.gov/vuln/detail/CVE-2025-23419 I feel hyper grossed out posting now

    Post summary

    The user simply lists two CVE identifiers with NVD links and expresses personal discomfort, without offering technical or actionable details.

    10000104
    2.9K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Appf5nginx---
Appf5nginx_plus---
Appf5nginx_plusr32--
Appf5nginx_plusr32--
Appf5nginx_plusr33--
Appf5nginx_plusr33--

Explore more