CVE-2025-3110
published 2026-07-08CVE-2025-3110: OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.45%
38.1th percentile
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | cbl2_kernel_5.15.86.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_kernel_5.10.174.1-1_on_cbl_mariner_1.0 | — | — |
| openvpn | access_server | 2.7.2 – 3.1.0 | — |
| openvpn | openvpn_access_server | 2.7.2 – 3.1.0 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv4.06.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat6.9MEDIUM
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
OpenVPN Access Server up to 3.1.0 HTTP Header Parser request smuggling
vuldb·2026-07-12·CVSS 7.5
CVE-2025-3110 [HIGH] OpenVPN Access Server up to 3.1.0 HTTP Header Parser request smuggling
A vulnerability identified as problematic has been detected in OpenVPN Access Server up to 3.1.0. This affects an unknown part of the component HTTP Header Parser. Performing a manipulation results in http request smuggling.
This vulnerability is reported as CVE-2025-3110. The attack is possible to be carried out remotely. No exploit exists.
GHSA
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
ghsa_unreviewed·2026-07-08
CVE-2025-3110 [MEDIUM] CWE-444 OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Red Hat
OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers
vendor_redhat·2026-07-08·CVSS 6.9
CVE-2025-3110 [MEDIUM] CWE-444 OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers
OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
A flaw in OpenVPN Access Server allows remote attackers to smuggle HTTP requests when the server operates behind a reverse proxy. The issue stems from the server accepting unstandardized bare line-feed sequences in HTTP headers.
Statement: A Moderate flaw in OpenVPN Access Server allows remote HTTP request smuggling when deployed behind a reverse proxy. This occurs because the server improperly accepts bare line-feed sequences in HTTP headers, causing proxy misinterpretation.
Mi
Microsoft
An issue was discovered in the Linux kernel through 5.16-rc6. _rtw_init_xmit_priv in drivers/staging/r8188eu/core/rtw_xmit.c lacks check of the return value of rtw_alloc_hwxmits() and will cause the n
vendor_msrc·2022-12-13·CVSS 5.5
CVE-2022-3110 [MEDIUM] CWE-476 An issue was discovered in the Linux kernel through 5.16-rc6. _rtw_init_xmit_priv in drivers/staging/r8188eu/core/rtw_xmit.c lacks check of the return value of rtw_alloc_hwxmits() and will cause the n
An issue was discovered in the Linux kernel through 5.16-rc6. _rtw_init_xmit_priv in drivers/staging/r8188eu/core/rtw_xmit.c lacks check of the return value of rtw_alloc_hwxmits() and will cause the null pointer dereference.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identi
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-3110 openvpn: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers [fedora-all]
bugzilla·2026-07-09·CVSS 6.9
CVE-2025-3110 [MEDIUM] CVE-2025-3110 openvpn: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers [fedora-all]
CVE-2025-3110 openvpn: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Discussion:
OpenVPN AS is a commercial product based on openvpn, but is not openvpn.
Bugzilla
CVE-2025-3110 openvpn: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers [epel-all]
bugzilla·2026-07-09·CVSS 6.9
CVE-2025-3110 [MEDIUM] CVE-2025-3110 openvpn: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers [epel-all]
CVE-2025-3110 openvpn: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Discussion:
OpenVPN AS is a commercial product based on openvpn, but is not openvpn.
Bugzilla
CVE-2025-3110 OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers
bugzilla·2026-07-08·CVSS 6.9
CVE-2025-3110 [MEDIUM] CVE-2025-3110 OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers
CVE-2025-3110 OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
2026-07-08
Published