Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3110

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy

A flaw in OpenVPN Access Server allows remote attackers to smuggle HTTP requests when the server operates behind a reverse proxy. The issue stems from the server accepting unstandardized bare line-feed sequences in HTTP headers.

Отчет

A Moderate flaw in OpenVPN Access Server allows remote HTTP request smuggling when deployed behind a reverse proxy. This occurs because the server improperly accepts bare line-feed sequences in HTTP headers, causing proxy misinterpretation.

Меры по смягчению последствий

To mitigate this issue, ensure that any reverse proxy deployed in front of OpenVPN Access Server is configured to strictly validate and normalize HTTP header fields, specifically rejecting or sanitizing bare line-feed sequences. Alternatively, consider restricting direct network access to the OpenVPN Access Server, bypassing the reverse proxy, if your deployment architecture allows for it without compromising other security requirements. Consult your reverse proxy's documentation for specific configuration options related to HTTP header parsing and normalization. Any changes to proxy configurations may require a service reload or restart to take effect, which could temporarily interrupt service.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2498148OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers

EPSS

Процентиль: 18%
0.00259
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 месяцев назад

OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy

CVSS3: 7.5
github
около 2 месяцев назад

OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy

EPSS

Процентиль: 18%
0.00259
Низкий

5.3 Medium

CVSS3