CVE-2025-9232
OpenSSL vulnerability analysis and mitigation

Overview

CVE-2025-9232 is an out-of-bounds read vulnerability discovered in OpenSSL's HTTP client API, disclosed on September 30, 2025. The vulnerability affects OpenSSL versions 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0, and 3.5.0, where an application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. The issue was discovered by Stanislav Fort from Aisle Research and has been assigned a Low severity rating (OpenSSL Advisory).

Technical details

The vulnerability is classified as an out-of-bounds read (CWE-125) that occurs specifically when processing HTTP requests with IPv6 addresses while the 'no_proxy' environment variable is set. The issue affects the HTTP client implementation in OpenSSL, which is used both directly by applications and by the OCSP client functions and CMP (Certificate Management Protocol) client implementation. The vulnerability has been assigned a CVSS v3.1 Base Score of 5.9 MEDIUM (Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) (NVD).

Impact

The primary impact of this vulnerability is the potential for a Denial of Service (DoS) condition through application crashes. The out-of-bounds read can trigger a crash which leads to Denial of Service for an application. However, the impact is limited as the vulnerability requires specific conditions: an attacker-controlled URL must be passed from an application to the OpenSSL function, and the user must have a 'no_proxy' environment variable set (OpenSSL Advisory).

Exploitability

The exploitability of this vulnerability is considered low due to several required conditions. The vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function, and the user must have a 'no_proxy' environment variable set. Additionally, while the HTTP client API functions can be used directly by applications and by OCSP client functions and CMP implementation, the URLs used by these implementations are unlikely to be controlled by an attacker (OpenSSL Advisory).

Mitigation and workarounds

The recommended mitigation is to upgrade to the fixed versions of OpenSSL. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.4, OpenSSL 3.4 users to 3.4.3, OpenSSL 3.3 users to 3.3.5, OpenSSL 3.2 users to 3.2.6, and OpenSSL 3.0 users to 3.0.18. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1, and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary (OpenSSL Advisory).

Community reactions

Multiple Linux distributions have responded to this vulnerability by releasing security updates. Ubuntu has issued security notices (USN-7786-1) addressing this vulnerability across multiple versions of their operating system, including Ubuntu 25.04, 24.04 LTS, 22.04 LTS, and others (Ubuntu Notice). Debian has also released security updates (DSA 6015-1) to address this vulnerability in their distributions (Debian Notice).

Additional resources


SourceThis report was generated using AI

Related OpenSSL vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-11999HIGH8.2
  • OpenSSL logoOpenSSL
  • seal-openssl
NoYesJun 25, 2026
CVE-2026-7383HIGH8.1
  • OpenSSL logoOpenSSL
  • openssl-c_rehash
NoYesJun 09, 2026
CVE-2026-54876HIGH7.5
  • OpenSSL logoOpenSSL
  • edk2
NoYesAug 05, 2026
CVE-2026-9076HIGH7.5
  • OpenSSL logoOpenSSL
  • openssl11-libs
NoYesJun 09, 2026
CVE-2026-45784MEDIUM5.1
  • Rust logoRust
  • rust
NoYesJul 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management