AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2025-3110

HIGH · CVSS 7.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

OpenVPN Access Server versions 2.7.2 to 3.1.0 are vulnerable to HTTP request smuggling due to improper handling of bare line-feed sequences in HTTP header values. This flaw can be exploited by remote attackers, potentially leading to unauthorized access or manipulation of requests when the server is behind a reverse proxy. Organizations using these versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2025-3110
Severity
HIGH
CVSS
7.5
EPSS
0.26%

Original NVD Description

OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy

Related CVEs

Other vulnerabilities affecting the same vendor(s)