Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-15467

67
FAUCET Score

CVE-2025-15467 is a critical stack buffer overflow vulnerability in OpenSSL versions 3.0, 3.3, 3.4, 3.5, and 3.6. It occurs when parsing maliciously crafted CMS AuthEnvelopedData or EnvelopedData messages that use AEAD ciphers, specifically due to an oversized Initialization Vector (IV) being copied into a fixed-size stack buffer. This vulnerability has a CVSS score of 9.8 (Critical) and can lead to Denial of Service or potentially remote code execution, as it triggers prior to authentication and does not require valid key material. While there is no confirmed active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness of its severe risk.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.0.0, < 3.0.19CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.1.0, < 3.3.6CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.4.0, < 3.4.4CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.5.0, < 3.5.5CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*
>= 3.6.0, < 3.6.1CPE matchmatch criteria
cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
47.62%
Probability of exploitation in next 30 days
EPSS Percentile
98.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.4762 is in the 96th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (65)

3cxpatch availablevia llm_extracted
Fixed in: 3.5.5
apolloconfigpatch availablevia llm_extracted
Fixed in: 3.5.5
applepatch availablevia llm_extracted
View patch
authlibpatch availablevia llm_extracted
Fixed in: 3.5.5
axllentpatch availablevia llm_extracted
Fixed in: 3.5.5
bacnetstackpatch availablevia llm_extracted
Fixed in: 3.5.5
boschpatch availablevia llm_extracted
Fixed in: OpenSSL 3.5.5
broadcompatch availablevia llm_extracted
Fixed in: 3.5.5
caddypatch availablevia llm_extracted
Fixed in: 3.5.5
clamavpatch availablevia llm_extracted
Fixed in: 3.5.5
clastixpatch availablevia llm_extracted
Fixed in: 3.5.5
debianpatch availablevia llm_extracted
Fixed in: 3.5.5
debianpatch availablevia llm_extracted
Fixed in: 3.13.0.2
View patch
denopatch availablevia llm_extracted
Fixed in: 3.5.5
dhis2patch availablevia llm_extracted
Fixed in: 3.5.5
elementpatch availablevia llm_extracted
View patch
esetpatch availablevia llm_extracted
View patch
ffmpegpatch availablevia llm_extracted
Fixed in: OpenSSL 3.5.5
filerisepatch availablevia llm_extracted
Fixed in: 3.5.5
github_advisorypatch availablevia nvd_reference
View patch
jitsipatch availablevia llm_extracted
Fixed in: 3.6.1
View patch
kamailiopatch availablevia llm_extracted
Fixed in: 3.5.5
kongpatch availablevia llm_extracted
Fixed in: 3.5.5
maxkbpatch availablevia llm_extracted
Fixed in: 3.5.5
nessuspatch availablevia llm_extracted
Fixed in: 3.5.5
netgearpatch availablevia llm_extracted
Fixed in: GKE
View patch
nodejspatch availablevia llm_extracted
View patch
nomadpatch availablevia llm_extracted
Fixed in: 3.5.5
pi_holepatch availablevia llm_extracted
Fixed in: 3.5.5
posthogpatch availablevia llm_extracted
Fixed in: OpenSSL 3.5.5
proxmoxpatch availablevia llm_extracted
Fixed in: 3.5.5
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10.0 Extended Update SupportFixed in: openssl-1:3.2.2-16.el10_0.6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/traefik-rhel9:sha256:8ea5bdee69a073ae7a741c6fe6d770d2ed87b0c0143885fca06a49d2a0036612
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/pluginregistry-rhel9:sha256:26dd9fb71bfad01a9a62e5cd83768146120efea71107c89cd8ce3361e7c73b4b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/openvsx-rhel9:sha256:d37e4c1f6f9bcebfb5ef805284b343d98d6e742adb589ade746321eade5863b4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.6 Extended Update SupportFixed in: openssl-1:3.2.2-7.el9_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: openssl-1:3.0.7-29.el9_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: openssl-1:3.0.7-18.el9_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: openssl-1:3.0.1-46.el9_0.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: openssl-1:3.5.1-7.el9_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/installer-rhel9:sha256:48cf7cf48dfadb17f9357bf1894a5d0393551a893faa8b0ea0e11fe1ffed497f
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/machineexec-rhel9:sha256:e724671480f0db043ff01c510cf3665833976806b3fb3fe64c4f186c3d445e7c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/jetbrains-ide-rhel9:sha256:b503ab30512cc9bf3cfa89f5a8b09a591b038f61c22d1b2777477f40bbdbec0b
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: openssl-1:3.5.1-7.el10_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/imagepuller-rhel9:sha256:0265615072824fe889c5bd3d1f40d8027c38236718ec3c994bc327583e4e4885
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/devspaces-rhel9-operator:sha256:c2c57991cc8bdda2882836401980b05d81bb254d8f6002cc345fbb985e43c258
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/dashboard-rhel9:sha256:20b0660092b3a3c069c06aae34f3306bcd655d58e33f7b8ce168aa3f21ccfef1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/configbump-rhel9:sha256:ffdb6bd87cb727dd99df7a9b3c160bd26fc113957bb22dc442cd38ba6b56d485
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.26Fixed in: devspaces/code-sshd-rhel9:sha256:4aff583803de7ebd055aa820c3167cf60fd65c4c5192cb86af65803c552871ec
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Insights proxy 1.5Fixed in: insights-proxy/insights-proxy-container-rhel9:sha256:975a1e501a8520df83f3f4114e72a71384ff1866ec99c7a45fffbf8c76ef5cbc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-ui-rhel9:sha256:26bb49a8e2e695d61192f04eb0db63efa8210bba20ea22b60e4e22d519d8b9e6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:519d4fe184cebe5152f840e9f609fa4705590656ac9bcace2e2e17622ab7e6a8
View patch
redhatpatch availablevia redhat_api
Product: Cost Management 4Fixed in: costmanagement/costmanagement-metrics-rhel9-operator:sha256:7424ae28625701b1441987b0457100505e273b2cbcb087bf0c046d7b2cc596c7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.20Fixed in: rhcos-4.20.9.6.202602050328-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.19Fixed in: rhcos-9.6.20260211-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.18Fixed in: rhcos-418.94.202602022246-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.17Fixed in: rhcos-417.94.202602090846-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: rhcos-416.94.202602101357-0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Core Services 2.4.62.SP3Fixed in: openssl
View patch
sophospatch availablevia llm_extracted
View patch
stripepatch availablevia llm_extracted
Fixed in: 3.5.5
tolgeepatch availablevia llm_extracted
Fixed in: 3.13.0.2
curlvendor investigatingvia llm_extracted
View patch
fortinetvendor investigatingvia vendor_rss
View patch
stripevendor investigatingvia llm_extracted
View patch

Vendor Advisories (38)

tolgeellm-tolgee-7597a57019e3455eHIGH

OpenSSL vulnerability addressed by bumping version

Mar 10, 2026
debianllm-debian-325bdf2ffedc7f23

OpenSSL vulnerability

Mar 10, 2026
fortinetfortinet:fortiguard.fortinet.com/psirt/#7117

OpenSSL CVE-2025-15467

Feb 21, 2026
netgearllm-netgear-5510306d43fb2097HIGH

Multiple security vulnerabilities in OpenSSL library, including critical RCE/DoS

Feb 20, 2026
fortinetfortinet:fortiguard.fortinet.com/psirt/FG-IR-26-076LOW

OpenSSL CVE-2025-15467

Jan 30, 2026
nodejsllm-nodejs-e82b00db8e56a562CRITICAL

FG-IR-26-076 OpenSSL

Jan 30, 2026
esetllm-eset-8649c6f038c4982cCRITICAL

FG-IR-26-076 OpenSSL CVE-2025-15467

Jan 30, 2026
applellm-apple-26f4f02fe6769989CRITICAL

FG-IR-26-076 OpenSSL

Jan 30, 2026
curlllm-curl-937e87b391bc683fCRITICAL

FG-IR-26-076 OpenSSL CVE-2025-15467

Jan 30, 2026
stripellm-stripe-1ceea29ade3a86faCRITICAL

OpenSSL

Jan 30, 2026
elementllm-element-ad1f8fdc0fad2500CRITICAL

FG-IR-26-076 OpenSSL CVE-2025-15467

Jan 30, 2026
sophosllm-sophos-1ec0daf81aafea7aHIGH

OpenSSL library vulnerabilities

Jan 29, 2026
redhatCVE-2025-15467Important

openssl: OpenSSL: Remote code execution or Denial of Service via oversized Initialization Vector in CMS parsing

Jan 27, 2026
jitsillm-jitsi-ee8b3f5e8652b4a8HIGH

Stack buffer overflow in CMS (Auth)EnvelopedData parsing

Jan 27, 2026
boschllm-bosch-d852bcdcde18597cHIGH

OpenSSL vulnerability

clamavllm-clamav-19edca26b6231b25

OpenSSL vulnerability addressed by version bump

denollm-deno-749d2714205b432e

OpenSSL Vulnerability

3cxllm-3cx-81af4f2935a4cf47

OpenSSL vulnerability

dhis2llm-dhis2-010f19978569d179

OpenSSL vulnerability

clastixllm-clastix-cc07d54582e3e9f2

OpenSSL vulnerability

caddyllm-caddy-1c71e2ed9d1664b2

OpenSSL vulnerability

proxmoxllm-proxmox-3742e7c9784554b3MEDIUM

OpenSSL vulnerability

pi_holellm-pi_hole-60c75387540a6f64HIGH

OpenSSL vulnerability

authlibllm-authlib-dca09f7cf007d57c

OpenSSL vulnerability requiring version bump

nessusllm-nessus-43d1e34a9933dc60

OpenSSL vulnerability

broadcomllm-broadcom-b428eb23799157f7HIGH

OpenSSL vulnerability

posthogllm-posthog-6ea5e18d61e7fa29

OpenSSL vulnerability

maxkbllm-maxkb-497d89d468409f1a

OpenSSL vulnerability

nomadllm-nomad-26156b84820d72b1

OpenSSL vulnerability

axllentllm-axllent-c5f4ed78a574d9b7

OpenSSL vulnerability

stripellm-stripe-5bd21432c81d28e4

OpenSSL vulnerability

nessusllm-nessus-d86110898ef07cd8

OpenSSL Vulnerability

ffmpegllm-ffmpeg-5cc29a0e9ac2299e

OpenSSL Vulnerability

bacnetstackllm-bacnetstack-7387d6eb0c1e8c98HIGH

OpenSSL vulnerability

kongllm-kong-382cef68f2e36c04MEDIUM

OpenSSL vulnerability

filerisellm-filerise-c0f272954c6aa7e9MEDIUM

OpenSSL vulnerability

kamailiollm-kamailio-af52f3b3ac1f8c37

OpenSSL vulnerability addressed by version bump

apolloconfigllm-apolloconfig-a3197f39e0c77f67

OpenSSL vulnerability

References

access.redhat.com / errata/RHSA-2026:1472
access.redhat.com / errata/RHSA-2026:1473
access.redhat.com / errata/RHSA-2026:1496
access.redhat.com / errata/RHSA-2026:1503
access.redhat.com / errata/RHSA-2026:1519
access.redhat.com / errata/RHSA-2026:1594
access.redhat.com / errata/RHSA-2026:1733
access.redhat.com / errata/RHSA-2026:1736
access.redhat.com / errata/RHSA-2026:2072
access.redhat.com / errata/RHSA-2026:2077
access.redhat.com / errata/RHSA-2026:2485
access.redhat.com / errata/RHSA-2026:2563
access.redhat.com / errata/RHSA-2026:2633
access.redhat.com / errata/RHSA-2026:2659
access.redhat.com / errata/RHSA-2026:2671
access.redhat.com / errata/RHSA-2026:2844
access.redhat.com / errata/RHSA-2026:2974
access.redhat.com / errata/RHSA-2026:2995
access.redhat.com / errata/RHSA-2026:3228
access.redhat.com / errata/RHSA-2026:3415
access.redhat.com / errata/RHSA-2026:3461
access.redhat.com / errata/RHSA-2026:3462
access.redhat.com / errata/RHSA-2026:4419
access.redhat.com / errata/RHSA-2026:4943
access.redhat.com / errata/RHSA-2026:6481
access.redhat.com / errata/RHSA-2026:7261
access.redhat.com / security/cve/CVE-2025-15467
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2025/cve-2025-15467.json
cert-portal.siemens.com / productcert/html/ssa-434797.html
cert-portal.siemens.com / productcert/html/ssa-734552.html
github.com / guiimoraes/CVE-2025-15467
ExploitThird Party Advisory
openwall.com / lists/oss-security/2026/01/27/10
Mailing List
openwall.com / lists/oss-security/2026/02/25/6
Mailing List
github.com / openssl/openssl/commit/2c8f0e5fa9b6ee5508a0349e4572ddb74db5a703
Patch
github.com / openssl/openssl/commit/5f26d4202f5b89664c5c3f3c62086276026ba9a9
Patch
github.com / openssl/openssl/commit/6ced0fe6b10faa560e410e3ee8d6c82f06c65ea3
Patch
github.com / openssl/openssl/commit/ce39170276daec87f55c39dad1f629b56344429e
Patch
github.com / openssl/openssl/commit/d0071a0799f20cc8101730145349ed4487c268dc
Patch
openssl-library.org / news/secadv/20260127.txt
Vendor Advisory