Out-of-bounds read in HTTP client no_proxy handling
Published Sep 30, 2025
5.9
MEDIUMCVSS 3.1
EPSS 2.00%
Description
Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address.
Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application.
The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker.
In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity.
The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0.
The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.
Affected products
-
- Version 3.0.16StatusaffectedConstraints<3.0.18
- Version 3.2.4StatusaffectedConstraints<3.2.6
- Version 3.3.3StatusaffectedConstraints<3.3.5
- Version 3.4.0StatusaffectedConstraints<3.4.3
- Version 3.5.0StatusaffectedConstraints<3.5.4
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
No data.
No data.
Red Hat Hardened Images
openssl-main-3.5.6-0.1.hum1
Fixed · RHSA-2026:7261
Red Hat Enterprise Linux 10
edk2
Fix deferred
Red Hat Enterprise Linux 10
openssl
Fix deferred
Red Hat Enterprise Linux 10
shim
Not affected
Red Hat Enterprise Linux 10
shim-unsigned-aarch64
Not affected
Red Hat Enterprise Linux 10
shim-unsigned-x64
Not affected
Red Hat Enterprise Linux 6
openssl
Not affected
Red Hat Enterprise Linux 7
openssl
Not affected
Red Hat Enterprise Linux 7
ovmf
Not affected
Red Hat Enterprise Linux 8
compat-openssl10
Not affected
Red Hat Enterprise Linux 8
edk2
Not affected
Red Hat Enterprise Linux 8
mingw-openssl
Not affected
Red Hat Enterprise Linux 8
openssl
Not affected
Red Hat Enterprise Linux 8
shim
Not affected
Red Hat Enterprise Linux 8
shim-unsigned-x64
Not affected
Red Hat Enterprise Linux 9
compat-openssl11
Not affected
Red Hat Enterprise Linux 9
edk2
Fix deferred
Red Hat Enterprise Linux 9
openssl
Fix deferred
Red Hat Enterprise Linux 9
shim
Not affected
Red Hat Enterprise Linux 9
shim-unsigned-aarch64
Not affected
Red Hat Enterprise Linux 9
shim-unsigned-x64
Not affected
Red Hat JBoss Core Services
openssl
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Fix deferred
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | openssl-main-3.5.6-0.1.hum1 | Fixed | RHSA-2026:7261 |
| Red Hat Enterprise Linux 10 | edk2 | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 10 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 10 | shim-unsigned-aarch64 | Not affected | n/a |
| Red Hat Enterprise Linux 10 | shim-unsigned-x64 | Not affected | n/a |
| Red Hat Enterprise Linux 6 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 7 | ovmf | Not affected | n/a |
| Red Hat Enterprise Linux 8 | compat-openssl10 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | edk2 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mingw-openssl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | openssl | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 8 | shim-unsigned-x64 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | compat-openssl11 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | edk2 | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | openssl | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | shim | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim-unsigned-aarch64 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | shim-unsigned-x64 | Not affected | n/a |
| Red Hat JBoss Core Services | openssl | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Fix deferred | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This vulnerability was rated as Low severity because exploitation requires a very specific set of conditions: the application must pass an attacker-controlled IPv6 URL to the OpenSSL HTTP client functions, and the no_proxy environment variable must be set by the user. Even under these conditions, the issue can only lead to an out-of-bounds read resulting in a crash, causing an application level denial of service. There is no potential for information disclosure or remote code execution. Additionally, typical use cases of the OpenSSL HTTP client (e.g., in OCSP or CMP) do not involve attacker-controlled URLs, which further reduces the likelihood of exploitation.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.00% (0.02001) | 80.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.05% (0.02046) | 78.62th | v5 (v2026.06.15) |
| Oct 1, 2025 | 0.03% (0.00028) | 6.63th | v4 (v2025.03.14) |
References (17)
- http://www.openwall.com/lists/oss-security/2025/09/30/5
- https://access.redhat.com/security/cve/CVE-2025-9232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2396056 Issue Tracking
- https://cert-portal.siemens.com/productcert/html/ssa-032379.html
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://cert-portal.siemens.com/productcert/html/ssa-089022.html
- https://cert-portal.siemens.com/productcert/html/ssa-253495.html
- https://cert-portal.siemens.com/productcert/html/ssa-485750.html
- https://cert-portal.siemens.com/productcert/html/ssa-585531.html
- https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35 patch
- https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b patch
- https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3 patch
- https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf patch
- https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0 patch
- https://nvd.nist.gov/vuln/detail/CVE-2025-9232
- https://openssl-library.org/news/secadv/20250930.txt vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2025-9232
Change history (0)
No recorded changes yet.