CVE-2025-55753

Description

An integer overflow in the case of failed ACME certificate renewal leads, after a number of failures (~30 days in default configurations), to the backoff timer becoming 0. Attempts to renew the certificate then are repeated without delays until it succeeds.This issue affects Apache HTTP Server: from 2.4.30 before 2.4.66.Users are recommended to upgrade to version 2.4.66, which fixes the issue.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
0.072

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2025-55753 are fixed in Apache 2.4.66Windows
Multiple vulnerabilities are fixed in Mac OS - Sonoma 14.8.5 (Software Update)(Auto Reboot)Mac
Multiple vulnerabilities are fixed in Mac OS Sequoia 15.7.5 (Software Update) (Auto Reboot)Mac
Multiple vulnerabilities are fixed in macOS Tahoe 26.4 (Software Update) (Auto Reboot)Mac

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-614082Mac OS - Sonoma 14.8.5 (Software Update)(Auto Reboot)
PATCH-614081Mac OS Sequoia 15.7.5 (Software Update) (Auto Reboot)
PATCH-614080macOS Tahoe 26.4 (Software Update) (Auto Reboot)(Deployment-Only)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234