CVE-2025-9232Disclosure

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. Impact summary: An out-of-bounds read can trigger a crash which leads to Denial of Service for an application. The OpenSSL HTTP client API functions can be used directly by applications but they are also used by the OCSP client functions and CMP (Certificate Management Protocol) client implementation in OpenSSL. However the URLs used by these implementations are unlikely to be controlled by an attacker. In this vulnerable code the out of bounds read can only trigger a crash. Furthermore the vulnerability requires an attacker-controlled URL to be passed from an application to the OpenSSL function and the user has to have a 'no_proxy' environment variable set. For the aforementioned reasons the issue was assessed as Low severity. The vulnerable code was introduced in the following patch releases: 3.0.16, 3.1.8, 3.2.4, 3.3.3, 3.4.0 and 3.5.0. The FIPS modules in 3.5, 3.4, 3.3, 3.2, 3.1 and 3.0 are not affected by this issue, as the HTTP client implementation is outside the OpenSSL FIPS module boundary.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-01-28); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-01-28: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-01-28: 101-2803-11
Signal classification2 categories
Disclosure
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-01-281
Disclosure1
2026-03-111
Patch1
Full discourse2 posts
  • GCP Weekly@gcpweekly
    Patch

    CVE-2022-27943 CVE-2023-2953 CVE-2023-31437 CVE-2023-31438 CVE-2023-31439 CVE-2023-45853 CVE-2024-2236 CVE-2024-2379 CVE-2024-26458 CVE-2024-26461 CVE-2025-0725 CVE-2025-10148 CVE-2025-27587 CVE-2025-62813 CVE-2025-9086 CVE-2025-9230 CVE-2025-9232 N/A Security fixes for 10/19

    Post summary

    The text lists a set of CVEs followed by a statement that security fixes were applied on 10/19, indicating a patch release.

    1000097
    1.8K followersView on X
  • guriguri@guriguri_dW
    Disclosure

    #IBMAIX #OpenSSL ■ Security Bulletin: AIX/VIOS is vulnerable to an out-of-bounds read (CVE-2025-9230, CVE-2025-9232) due to OpenSSL https://www.ibm.com/support/pages/node/7254361 > Modified date: 14 January 2026

    Post summary

    IBM’s AIX/VIOS platform has been disclosed as vulnerable to out‑of‑bounds read flaws in OpenSSL (CVE‑2025‑9230/9232), as detailed in a recent security bulletin.

    0000061
    122 followersView on X

Explore more