Junglewise Threat Intelligence

CVE-2025-9232: OpenSSL out-of-bounds read in HTTP client IPv6 URL handling

CVE-2025-9232 · Severity: medium · CVSS 5.9 · Published 2025-09-30

Technologies: OpenSSL Foundation OpenSSL.

Executive brief

OpenSSL is a widely used security library that enables encrypted communications for websites and applications. A vulnerability in its web-client component could allow an attacker to crash an application by providing a specially formatted web address (URL) containing an IPv6 address. This would result in a denial-of-service, making the affected service unavailable to users.

Technical details

An out-of-bounds read exists in the `use_proxy` function within `crypto/http/http_lib.c`. The vulnerability is caused by a missing NUL terminator after a `strncpy` call when stripping brackets from an IPv6 address in the authority component of a URL. An attacker who can control the URL passed to OpenSSL's HTTP, OCSP, or CMP client functions can trigger this read, potentially causing a segmentation fault and Denial of Service. Exploitation requires the 'no_proxy' environment variable to be configured on the host. The issue has been patched in OpenSSL versions 3.5.4, 3.4.3, 3.3.5, 3.2.6, and 3.0.18.

Affected products

  • OpenSSL Foundation OpenSSL 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0, 3.5.0

Timeline

  • 2025-09-30: advisory: OpenSSL Security Advisory published
  • 2025-09-30: patched

References