CVE-2025-66037 is a medium-severity out-of-bounds heap read vulnerability affecting OpenSC versions prior to 0.27.0. This flaw occurs in the X.509/SPKI handling path when processing specially crafted input, leading to a zero-length buffer being allocated and then read past its end. Rated with a CVSS score of 6.8, successful exploitation requires physical access to the system but can result in high impact to confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code, or inclusion on the CISA KEV catalog. The issue has been addressed in OpenSC version 0.27.0, and community discussions reflect awareness of the patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.27.0CPE matchmatch criteria | cpe:2.3:a:opensc_project:opensc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.