CVE-2025-15468General(openssl / openssl)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: If an application using the SSL_CIPHER_find() function in a QUIC protocol client or server receives an unknown cipher suite from the peer, a NULL dereference occurs. Impact summary: A NULL pointer dereference leads to abnormal termination of the running process causing Denial of Service. Some applications call SSL_CIPHER_find() from the client_hello_cb callback on the cipher ID received from the peer. If this is done with an SSL object implementing the QUIC protocol, NULL pointer dereference will happen if the examined cipher ID is unknown or unsupported. As it is not very common to call this function in applications using the QUIC protocol and the worst outcome is Denial of Service, the issue was assessed as Low severity. The vulnerable code was introduced in the 3.2 version with the addition of the QUIC protocol support. The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the QUIC implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-01-27); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-01-27: 1Mentions · 2026-02-19: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Patch / Workaround · 2026-03-14: 1Patch / Workaround · 2026-03-15: 1Technical Details · 2026-02-19: 101-2702-1903-1303-1403-15
Signal classification3 categories
General
240.0%
Patch
240.0%
Disclosure
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-01-271
General1
2026-02-191
Disclosure1
2026-03-131
General1
2026-03-141
Patch1
2026-03-151
Patch1
Full discourse5 posts
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-15468 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/415 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The post indicates that CVE‑2025‑15468 has been removed from recent AWS Lambda base images, implying a patch or mitigation has been applied.

    00000143
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Patch

    🔍 Lambda Watchdog detected that CVE-2025-15468 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/415 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    AWS has removed vulnerability CVE-2025-15468 from its latest Lambda base images, indicating a patch or mitigation, with no evidence of active exploitation or PoC code.

    00000140
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-15468 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/415 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE-2025-15468 is no longer found in the latest AWS Lambda base image scans, indicating the issue has been addressed in the images.

    00000127
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2025-15468 impacts openssl-fips-provider-latest in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/415 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE (CVE‑2025‑15468) affecting openssl‑fips‑provider‑latest in 40 AWS Lambda base images has been reported, with details linked to a GitHub issue and LambdaWatchdog.

    0000036
    30 followersView on X
  • 〒@teenigma_
    General

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    The advisory merely lists OpenSSL CVE severities and a link for more details, with no evidence of exploitation, patching, or technical specifics.

    00000156
    348 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more