CVE-2025-3110Disclosure(openvpn / openvpn_access_server)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openvpn_access_server

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-07-08); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
openvpn_access_server

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-07-08: 2Mentions · 2026-09-30: 1Technical Details · 2026-07-08: 207-0809-30
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • DFIR Lab@DFIR_Lab

    🚨 HIGH severity CVE-2025-3110 (CVSS 7.5) OpenVPN Access Server 2.7.2-3.1.0 vulnerable to HTTP request smuggling via bare line-feed sequences when behind reverse proxy. Remote exploitation, no auth required. #CVE #Vulnerability #PatchNow https://t.co/GAomLyxNeV

    0000037
    143 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-3110 OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when d… https://www.cve.org/CVERecord?id=CVE-2025-3110 ----- Traducción: CVE-2025-3110 Ope… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2025-3110, detailing its request smuggling flaw in OpenVPN Access Server, but offers no exploit code, patch info, or evidence of active attacks.

    0000037
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-3110 OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when d… https://www.cve.org/CVERecord?id=CVE-2025-3110

    Post summary

    The passage announces CVE‑2025‑3110, describing its technical details and impact but provides no evidence of active exploitation or available PoC.

    00000730
    57.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopenvpnopenvpn_access_server---

Explore more