CVE-2025-66199General(openssl / openssl)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch openssl openssl systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: A TLS 1.3 connection using certificate compression can be forced to allocate a large buffer before decompression without checking against the configured certificate size limit. Impact summary: An attacker can cause per-connection memory allocations of up to approximately 22 MiB and extra CPU work, potentially leading to service degradation or resource exhaustion (Denial of Service). In affected configurations, the peer-supplied uncompressed certificate length from a CompressedCertificate message is used to grow a heap buffer prior to decompression. This length is not bounded by the max_cert_list setting, which otherwise constrains certificate message sizes. An attacker can exploit this to cause large per-connection allocations followed by handshake failure. No memory corruption or information disclosure occurs. This issue only affects builds where TLS 1.3 certificate compression is compiled in (i.e., not OPENSSL_NO_COMP_ALG) and at least one compression algorithm (brotli, zlib, or zstd) is available, and where the compression extension is negotiated. Both clients receiving a server CompressedCertificate and servers in mutual TLS scenarios receiving a client CompressedCertificate are affected. Servers that do not request client certificates are not vulnerable to client-initiated attacks. Users can mitigate this issue by setting SSL_OP_NO_RX_CERTIFICATE_COMPRESSION to disable receiving compressed certificates. The FIPS modules in 3.6, 3.5, 3.4 and 3.3 are not affected by this issue, as the TLS implementation is outside the OpenSSL FIPS module boundary. OpenSSL 3.6, 3.5, 3.4 and 3.3 are vulnerable to this issue. OpenSSL 3.0, 1.1.1 and 1.0.2 are not affected by this issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openssl

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 4d ago at 2 mentions (2026-01-27); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
openssl

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-01-27: 2Mentions · 2026-02-19: 1Mentions · 2026-03-13: 1Mentions · 2026-03-14: 1Mentions · 2026-03-15: 1Patch / Workaround · 2026-01-27: 101-2702-1903-1303-1403-15
Signal classification3 categories
General
350.0%
Disclosure
233.3%
Patch
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1Patch1
2026-02-191
Disclosure1
2026-03-131
General1
2026-03-141
General1
2026-03-151
General1
Full discourse6 posts
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-66199 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/416 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    Lambda Watchdog reports that CVE‑2025‑66199 is no longer detected in current AWS Lambda base images, indicating the vulnerability has likely been addressed or is no longer present.

    00000147
    32 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-66199 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/416 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The update notes that CVE-2025-66199 is no longer detected in the latest AWS Lambda base images, without additional exploit, patch, or technical details.

    00000148
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    General

    🔍 Lambda Watchdog detected that CVE-2025-66199 is no longer present in latest AWS Lambda base image scans. https://github.com/aws/aws-lambda-base-images/issues/416 #AWS #Lambda #Security #CVE #DevOps #SecOps

    Post summary

    The tweet notes that CVE‑2025‑66199 is not detected in the latest AWS Lambda base images, but no further exploit, patch, or technical detail is provided.

    00000135
    31 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2025-66199 impacts openssl-fips-provider-latest in 40 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/416 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high severity CVE (CVE‑2025‑66199) affecting the openssl‑fips‑provider‑latest component in 40 AWS Lambda base images has been reported, with details posted on GitHub and Lambdawatchdog.

    0000040
    30 followersView on X
  • 〒@teenigma_
    Disclosure

    oss-sec: OpenSSL Security Advisory Moderate: CVE-2025-11187 High: CVE-2025-15467 Low: CVE-2025-15468, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://seclists.org/oss-sec/2026/q1/123

    Post summary

    The advisory lists multiple OpenSSL CVEs with their severity levels but offers no further technical or remediation information.

    00000156
    348 followersView on X
  • TRONCAL Yannick@ytroncal
    Patch

    OpenSSL 3.6.1 Is Now Available with Important Security Patches and Bug Fixes This release addresses CVE-2025-11187, CVE-2025-15467, CVE-2025-15469, CVE-2025-66199, CVE-2025-68160, CVE-2025-69418, and CVE-2025-69419. https://9to5linux.com/openssl-3-6-1-is-now-available-with-important-security-patches-and-bug-fixes

    Post summary

    OpenSSL 3.6.1 release includes patches for several CVEs, emphasizing the availability of important security fixes.

    00000158
    130 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appopensslopenssl---

Explore more