logo

Resolving a Mutual TLS session resumption vulnerability

ID: 88a5528a-9a84-5880-9b41-d35d2be19fb1

STIX ID: report--88a5528a-9a84-5880-9b41-d35d2be19fb1

Feed Name: Cloudflare Blog

Threat Score
50/100

Date Published: 2025-02-07

Date Updated: 2026-04-27

Author: Matt Bullock

...
...

Cloudflare disclosed a vulnerability (CVE-2025-23419) in its mTLS session resumption handling that allowed a client authenticated to one Cloudflare zone to reuse a resumed TLS session to access another zone without revalidating the client certificate. The issue stemmed from incorrect use of BoringSSL session partitioning APIs; Cloudflare mitigated the problem within 32 hours by disabling TLS session resumption for mTLS, noting no evidence of active exploitation and providing guidance for additional logging and hardening.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.