Executive brief
OpenSSL is a widely used security library that enables encrypted communications for websites and applications. A vulnerability in its web-client component could allow an attacker to crash an application by providing a specially formatted web address (URL) containing an IPv6 address. This would result in a denial-of-service, making the affected service unavailable to users.
Technical details
An out-of-bounds read exists in the `use_proxy` function within `crypto/http/http_lib.c`. The vulnerability is caused by a missing NUL terminator after a `strncpy` call when stripping brackets from an IPv6 address in the authority component of a URL. An attacker who can control the URL passed to OpenSSL's HTTP, OCSP, or CMP client functions can trigger this read, potentially causing a segmentation fault and Denial of Service. Exploitation requires the 'no_proxy' environment variable to be configured on the host. The issue has been patched in OpenSSL versions 3.5.4, 3.4.3, 3.3.5, 3.2.6, and 3.0.18.
Affected products
- OpenSSL Foundation OpenSSL 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0, 3.5.0
Timeline
- 2025-09-30: advisory: OpenSSL Security Advisory published
- 2025-09-30: patched
References
- https://github.com/openssl/openssl/commit/2b4ec20e47959170422922eaff25346d362dcb35
- https://github.com/openssl/openssl/commit/654dc11d23468a74fc8ea4672b702dd3feb7be4b
- https://github.com/openssl/openssl/commit/7cf21a30513c9e43c4bc3836c237cf086e194af3
- https://github.com/openssl/openssl/commit/89e790ac431125a4849992858490bed6b225eadf
- https://github.com/openssl/openssl/commit/bbf38c034cdabd0a13330abcc4855c866f53d2e0
- https://openssl-library.org/news/secadv/20250930.txt
- http://www.openwall.com/lists/oss-security/2025/09/30/5