CVE-2025-8095Disclosure

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications.  OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-257

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-14); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-14: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-19: 104-1404-1904-21
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-141
Disclosure1
2026-04-191
General1
2026-04-211
Disclosure1
Full discourse3 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-8095: Rec... OECH1's crypto weakness turns OpenEdge "obfuscation" into plaintext with extra steps - mass credential exposure incoming. #OpenEdge #ProgressSoftware. https://zerodaysignal.com/vulnerability/CVE-2025-8095 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The announcement describes CVE‑2025‑8095 as a crypto weakness in OpenEdge that could expose credentials, with details linked to an external vulnerability page.

    00010184
    218 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Progress ❗ CVE-2025-8095 ❗ CVE-2025-7389 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-progress-software/ https://t.co/AhhP1Y0iDi

    Post summary

    The message announces two CVEs (CVE-2025-8095 and CVE-2025-7389) affecting Progress products and provides a link for additional information.

    00000321
    6.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2025-8095 The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored enco… https://www.cve.org/CVERecord?id=CVE-2025-8095

    Post summary

    The post highlights that the OECH1 prefix encoding used by OpenEdge is cryptographically weak and references the CVE record but provides no exploit, patch, PoC, or evidence of active exploitation.

    00000135
    57.2K followersView on X

Explore more