PoC Archive PoC Archive

tag

Client-Certificate

  • CVE-2025-23048 web CRITICAL 9.1

    Apache mod_ssl TLS 1.3 Session Resumption Client Certificate Bypass (CVE-2025-23048)

    CVE-2025-23048 is a client certificate authentication bypass in Apache HTTP Server's modssl that occurs when TLS 1.3 session resumption (session tickets/PSK) is used across virtual hosts configured with different SSLCACertificateFile directives. The root…

    Patched 2026-07-06
  • CVE-2026-8932 network LOW

    libcurl mTLS Connection Reuse Authentication Bypass (CVE-2026-8932)

    CVE-2026-8932 is a Low-severity authentication bypass in libcurl's TLS connection reuse logic. Certain mTLS private-key configuration parameters (key file path, key type, key password) were omitted from the connection-matching comparison performed when…

    Patched 2026-06-30