HIGH
OpenEMR Has Disabled SSL Certificate Verification in HTTP Client
Published Feb 25, 2026
8.1
HIGHCVSS 3.1
EPSS 0.24%
Description
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 7.0.4, OpenEMR's HTTP client wrapper (`oeHttp`/`oeHttpRequest`) disables SSL/TLS certificate verification by default (`verify: false`), making all external HTTPS connections vulnerable to man-in-the-middle (MITM) attacks. This affects communication with government healthcare APIs and user-configurable external services, potentially exposing Protected Health Information (PHI). Version 7.0.4 fixes the issue.
Affected products
-
- Version < 7.0.4StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://github.com/openemr/openemr/commit/22f8e53e5769a88b7a16cb223bd197d044c84e5a x_refsource_MISCPatch
- https://github.com/openemr/openemr/security/advisories/GHSA-2g6h-725p-pqhp x_refsource_CONFIRMExploitVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/openemr/openemr/commit/22f8e53e5769a88b7a16cb223bd197d044c84e5a | x_refsource_MISCPatch | |
| https://github.com/openemr/openemr/security/advisories/GHSA-2g6h-725p-pqhp | x_refsource_CONFIRMExploitVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Feb 25, 2026
Updated Feb 27, 2026
Reserved Dec 11, 2025
Link CVE-2025-67752
CISA Vulnrichment
Updated Feb 27, 2026