CVE-2025-9232
published 2025-09-30CVE-2025-9232: Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and…
PriorityP336medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
2.09%
79.6th percentile
Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is set and
the host portion of the authority component of the HTTP URL is an IPv6 address.
Impact summary: An out-of-bounds read can trigger a crash which leads to
Denial of Service for an application.
The OpenSSL HTTP client API functions can be used directly by applications
but they are also used by the OCSP client functions and CMP (Certificate
Management Protocol) client implementation in OpenSSL. However the URLs used
by these implementations are unlikely to be controlled by an attacker.
In this vulnerable code the out of bounds read can only trigger a crash.
Furthermore the vulnerability requires an attacker-controlled URL to be
passed from an application to the OpenSSL function and the user has to have
a 'no_proxy' environment variable set. For the aforementioned reasons the
issue was assessed as Low severity.
The vulnerable code was introduced in the following patch releases:
3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.
The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this
issue, as the HTTP client implementation is outside the OpenSSL FIPS module
boundary.
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssl | < openssl 3.0.17-1~deb12u3 (bookworm) | openssl 3.0.17-1~deb12u3 (bookworm) |
| msrc | azl3_cloud-hypervisor_41.0.139-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_edk2_20240524git3e722403cd16-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_openssl_3.3.3-3_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-21_on_azure_linux_3.0 | — | — |
| msrc | azl3_qemu_8.2.0-23_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-22_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.75.0-24_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_rust_1.90.0-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cloud-hypervisor-cvm_38.0.72.2-5_on_cbl_mariner_2.0 | — | — |
| openssl | openssl | >= 0 < 3.0.19-r0 | 3.0.19-r0 |
| openssl | openssl | >= 0 < 3.1.8-r1 | 3.1.8-r1 |
| openssl | openssl | >= 0 < 3.3.5-r0 | 3.3.5-r0 |
| openssl | openssl | >= 0 < 3.3.5-r0 | 3.3.5-r0 |
| openssl | openssl | >= 0 < 3.5.4-r0 | 3.5.4-r0 |
| openssl | openssl | >= 0 < 3.5.4-r0 | 3.5.4-r0 |
| openssl | openssl | >= 0 < 3.0.17-1~deb12u3 | 3.0.17-1~deb12u3 |
| openssl | openssl | >= 0 < 3.5.1-1+deb13u1 | 3.5.1-1+deb13u1 |
| openssl | openssl | >= 0 < 3.5.4-1 | 3.5.4-1 |
| openssl | openssl | >= 0 < 3.0.2-0ubuntu1.20 | 3.0.2-0ubuntu1.20 |
| openssl | openssl | >= 0 < 3.0.13-0ubuntu3.6 | 3.0.13-0ubuntu3.6 |
| openssl | openssl | >= 0 < 1.0.1f-1ubuntu2.27+esm11 | 1.0.1f-1ubuntu2.27+esm11 |
| openssl | openssl | >= 0 < 1.0.2g-1ubuntu4.20+esm13 | 1.0.2g-1ubuntu4.20+esm13 |
| openssl | openssl | >= 0 < 1.1.1-1ubuntu2.1~18.04.23+esm6 | 1.1.1-1ubuntu2.1~18.04.23+esm6 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
edk2 regression
osv·2025-11-28·CVSS 7.4
CVE-2023-45236 [HIGH] edk2 regression
edk2 regression
USN-7894-1 fixed vulnerabilities in EDK II. The update introduced a
regression in the UEFI network boot. This update reverts the corresponding
fixes for CVE-2023-45236 and CVE-2023-45237 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-1298)
It was discovered that
OSV
edk2 vulnerabilities
osv·2025-11-26·CVSS 7.4
CVE-2023-45236 [HIGH] edk2 vulnerabilities
edk2 vulnerabilities
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-1298)
It was discovered that the EDK II PE/COFF loader incorrectly handled
certain memory operations. An attacker could possibly use this issue to
cause a denial of service, obtain sensitive information, or execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2024-38
OSV
CVE-2025-9232: Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is
osv·2025-09-30·CVSS 5.9
CVE-2025-9232 [MEDIUM] CVE-2025-9232: Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is
Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed fro
OSV
openssl, openssl1.0 vulnerabilities
osv·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] openssl, openssl1.0 vulnerabilities
openssl, openssl1.0 vulnerabilities
Stanislav Fort discovered that OpenSSL incorrectly handled memory when
trying to decrypt CMS messages encrypted with password-based encryption. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2025-9230)
Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2
signature computations on ARM platforms. A remote attacker could possibly
use this issue to recover private data. This issue only affected Ubuntu
25.04. (CVE-2025-9231)
Stanislav Fort discovered that OpenSSL incorrectly handled memory during
HTTP requests when "no_proxy" environment variable is set. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 25.04. (CVE-2025-9232)
OSV
CVE-2025-9232: Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is
osv·2025-09-30·CVSS 5.9
CVE-2025-9232 [MEDIUM] CVE-2025-9232: Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is
Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is set and
the host portion of the authority component of the HTTP URL is an IPv6 address.
Impact summary: An out-of-bounds read can trigger a crash which leads to
Denial of Service for an application.
The OpenSSL HTTP client API functions can be used directly by applications
but they are also used by the OCSP client functions and CMP (Certificate
Management Protocol) client implementation in OpenSSL. However the URLs used
by these implementations are unlikely to be controlled by an attacker.
In this vulnerable code the out of bounds read can only trigger a crash.
Furthermore the vulnerability requires an attacker-controlled URL to be
passed
GHSA
GHSA-76r2-c3cg-f5r9: Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is
ghsa_unreviewed·2025-09-30
CVE-2025-9232 [MEDIUM] CWE-125 GHSA-76r2-c3cg-f5r9: Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is
Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is set and
the host portion of the authority component of the HTTP URL is an IPv6 address.
Impact summary: An out-of-bounds read can trigger a crash which leads to
Denial of Service for an application.
The OpenSSL HTTP client API functions can be used directly by applications
but they are also used by the OCSP client functions and CMP (Certificate
Management Protocol) client implementation in OpenSSL. However the URLs used
by these implementations are unlikely to be controlled by an attacker.
In this vulnerable code the out of bounds read can only trigger a crash.
Furthermore the vulnerability requires an attacker-controlled URL to be
passed
CISA ICS
Siemens SIDIS Prime
cisa_ics·2026-03-12·CVSS 7.5
[HIGH] Siemens SIDIS Prime
ICS Advisory
##
Siemens SIDIS Prime
Release DateMarch 12, 2026
Alert CodeICSA-26-071-03
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
SIDIS Prime before V4.0.800 is affected by multiple vulnerabilities in the components OpenSSL, SQLite, and several Node.js packages as described below. Siemens has released a new version of SIDIS Prime and recommends to update to the latest version.
The following versions of Siemens SIDIS Prime are affected:
- SIDIS Prime vers:intdot/<4.0.800 (CVE-2024-29857, CVE-2024-30171, CVE-2024-30172, CVE-2024-41996, CVE-2025-6965, CVE-2025-7783, CVE-2025-9230, CVE-2025-9232, CVE-2025-9670, CVE-2025-12816, CVE-2025-15284, CVE-2025-58751, CVE-2025-58752, CVE-2025-58754, CVE-202
Ubuntu
EDK II regression
vendor_ubuntu·2025-11-28·CVSS 5.8
CVE-2023-45236 [MEDIUM] EDK II regression
Title: EDK II regression
Summary: USN-7894-1 introduced a regression in EDK II
USN-7894-1 fixed vulnerabilities in EDK II. The update introduced a
regression in the UEFI network boot. This update reverts the corresponding
fixes for CVE-2023-45236 and CVE-2023-45237 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS
Ubuntu
EDK II vulnerabilities
vendor_ubuntu·2025-11-26·CVSS 7.4
CVE-2023-45236 [HIGH] EDK II vulnerabilities
Title: EDK II vulnerabilities
Summary: Several security issues were fixed in EDK II.
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-1298)
It was discovered that the EDK II PE/COFF loader incorrectly handled
certain memory operations. An attacker could possibly use this issue to
cause a denial of service, obtain sensitive information, or execute
arbitrary code. This issue o
BSD
FreeBSD-SA-25:08.openssl: Multiple vulnerabilities in OpenSSL
bsd_advisories·2025-09-30·CVSS 7.5
CVE-2025-9230 [HIGH] FreeBSD-SA-25:08.openssl: Multiple vulnerabilities in OpenSSL
FreeBSD-SA-25:08.openssl Security Advisory
The FreeBSD Project
Topic: Multiple vulnerabilities in OpenSSL
Category: contrib
Module: openssl
Announced: 2025-09-30
Credits: Stanislav Fort (Aisle Research)
Affects: All supported versions of FreeBSD.
Corrected: 2025-09-30 15:26:14 UTC (stable/15, 15.0-ALPHA4)
2025-09-30 15:28:38 UTC (stable/14, 14.3-STABLE)
2025-09-30 15:37:16 UTC (releng/14.3, 14.3-RELEASE-p4)
2025-09-30 15:37:25 UTC (releng/14.2, 14.2-RELEASE-p7)
2025-09-30 15:30:02 UTC (stable/13, 13.5-STABLE)
2025-09-30 15:37:35 UTC (releng/13.5, 13.5-RELEASE-p5)
CVE Name: CVE-2025-9230, CVE-2025-9231, CVE-2025-9232
For general information regarding FreeBSD Security Advisories,
including descriptions of the fields above, security branches, and the
following sections, please visit .
I.
Red Hat
openssl: Out-of-bounds read in HTTP client no_proxy handling
vendor_redhat·2025-09-30·CVSS 5.9
CVE-2025-9232 [MEDIUM] CWE-125 openssl: Out-of-bounds read in HTTP client no_proxy handling
openssl: Out-of-bounds read in HTTP client no_proxy handling
Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the 'no_proxy' environment variable is set and
the host portion of the authority component of the HTTP URL is an IPv6 address.
Impact summary: An out-of-bounds read can trigger a crash which leads to
Denial of Service for an application.
The OpenSSL HTTP client API functions can be used directly by applications
but they are also used by the OCSP client functions and CMP (Certificate
Management Protocol) client implementation in OpenSSL. However the URLs used
by these implementations are unlikely to be controlled by an attacker.
In this vulnerable code the out of bounds read can only trigger a crash.
Furthermore the vuln
Ubuntu
OpenSSL vulnerabilities
vendor_ubuntu·2025-09-30·CVSS 7.5
CVE-2025-9232 [HIGH] OpenSSL vulnerabilities
Title: OpenSSL vulnerabilities
Summary: Several security issues were fixed in OpenSSL.
Stanislav Fort discovered that OpenSSL incorrectly handled memory when
trying to decrypt CMS messages encrypted with password-based encryption. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. (CVE-2025-9230)
Stanislav Fort discovered that OpenSSL had a timing side-channel in SM2
signature computations on ARM platforms. A remote attacker could possibly
use this issue to recover private data. This issue only affected Ubuntu
25.04. (CVE-2025-9231)
Stanislav Fort discovered that OpenSSL incorrectly handled memory during
HTTP requests when "no_proxy" environment variable is set. An attacker
could possibly use this issue to cause a denial of service. This i
Microsoft
Out-of-bounds read in HTTP client no_proxy handling
vendor_msrc·2025-09-09·CVSS 5.9
CVE-2025-9232 [MEDIUM] CWE-125 Out-of-bounds read in HTTP client no_proxy handling
Out-of-bounds read in HTTP client no_proxy handling
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
openssl: openssl
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn
Debian
CVE-2025-9232: openssl - Issue summary: An application using the OpenSSL HTTP client API functions may tr...
vendor_debian·2025·CVSS 5.9
CVE-2025-9232 [MEDIUM] CVE-2025-9232: openssl - Issue summary: An application using the OpenSSL HTTP client API functions may tr...
Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed fro
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-9232 mingw-openssl: Out-of-bounds read in HTTP client no_proxy handling [fedora-42]
bugzilla·2025-10-01·CVSS 5.9
CVE-2025-9232 [MEDIUM] CVE-2025-9232 mingw-openssl: Out-of-bounds read in HTTP client no_proxy handling [fedora-42]
CVE-2025-9232 mingw-openssl: Out-of-bounds read in HTTP client no_proxy handling [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all
Bugzilla
CVE-2025-9232 edk2: Out-of-bounds read in HTTP client no_proxy handling [fedora-42]
bugzilla·2025-10-01·CVSS 5.9
CVE-2025-9232 [MEDIUM] CVE-2025-9232 edk2: Out-of-bounds read in HTTP client no_proxy handling [fedora-42]
CVE-2025-9232 edk2: Out-of-bounds read in HTTP client no_proxy handling [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug repo
Bugzilla
CVE-2025-9232 openssl: Out-of-bounds read in HTTP client no_proxy handling
bugzilla·2025-09-17·CVSS 5.9
CVE-2025-9232 [MEDIUM] CVE-2025-9232 openssl: Out-of-bounds read in HTTP client no_proxy handling
CVE-2025-9232 openssl: Out-of-bounds read in HTTP client no_proxy handling
Issue summary: An application using the OpenSSL HTTP client API functions may
trigger an out-of-bounds read if the "no_proxy" environment variable is set and
the host portion of the authority component of the HTTP URL is an IPv6 address.
Impact summary: An out-of-bounds read can trigger a crash which leads to
Denial of Service for an application.
The OpenSSL HTTP client API functions can be used directly by applications
but they are also used by the OCSP client functions and CMP (Certificate
Management Protocol) client implementation in OpenSSL. However the URLs used
by these implementations are unlikely to be controlled by an attacker.
In this vulnerable code the out of bounds read can only trigger a crash.
Fur
https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4bhttps://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadfhttps://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0https://openssl-library.org/news/secadv/20250930.txthttp://www.openwall.com/lists/oss-security/2025/09/30/5https://cert-portal.siemens.com/productcert/html/ssa-032379.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-089022.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-253495.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-485750.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-585531.html
2025-09-30
Published