High severity7.5NVD Advisory· Published Jul 8, 2026· Updated Jul 10, 2026
CVE-2025-3110
CVE-2025-3110
Description
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Affected products
2cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openvpn:openvpn_access_server:*:*:*:*:*:*:*:*range: >=2.7.2,<=3.1.0
- (no CPE)range: 2.7.2 - 3.1.0
Patches
Vulnerability mechanics
References
1- openvpn.net/as-docs/as-3-2-release-notes.htmlnvdRelease Notes
News mentions
0No linked articles in our index yet.