CVE-2025-9232 is a low-severity out-of-bounds read vulnerability affecting applications using OpenSSL HTTP client API functions, specifically when the 'no_proxy' environment variable is set and the HTTP URL's host is an IPv6 address. This flaw can lead to a Denial of Service (DoS) due to application crashes. The vulnerability has a CVSS score of 5.9 (Medium) and requires an attacker-controlled URL and a specific user environment variable. There is no evidence of active exploitation, and no public exploit code is available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.16, < 3.0.18CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.2.4, < 3.2.6CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.3.3, < 3.3.5CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.4.0, < 3.4.3CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
>= 3.5.0, < 3.5.4CPE match | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP Device Manager Vulnerability Update (5.0.16)
Mar 9, 2026HP ThinPro 8.1 SP9 Security Updates
Feb 2, 2026openssl: Out-of-bounds read in HTTP client no_proxy handling
Sep 30, 2025Out-of-bounds read in HTTP client no_proxy handling
Sep 30, 2025Out-of-bounds read in HTTP client no_proxy handling
Sep 9, 2025