Description
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Published: 2026-07-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line‑feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy. This flaw falls under HTTP request smuggling and request manipulation weaknesses.

Affected Systems

All OpenVPN Access Server installations from version 2.7.2 up to and including 3.1.0 are affected. Any deployment that has not been upgraded beyond 3.1.0 faces the same risk.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate risk. The EPSS score of <1% suggests a very low but nonzero likelihood of exploitation. This vulnerability is not listed in CISA’s KEV catalog. It arises when a client sends header values containing raw line‑feed characters to an Access Server behind a reverse proxy, enabling HTTP request smuggling. The attack vector is remote, requiring the ability to craft and send HTTP requests to the server.

Generated by OpenCVE AI on July 28, 2026 at 09:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade OpenVPN Access Server to the latest supported version where this issue has been fixed.
  • If an upgrade is not possible, configure your reverse proxy to strip or normalize raw line‑feed characters from HTTP header values before forwarding requests to the Access Server.
  • Review and harden reverse proxy rules to reject or encode any raw line‑feed characters in header values.

Generated by OpenCVE AI on July 28, 2026 at 09:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Openvpn
Openvpn openvpn Access Server
Vendors & Products Openvpn
Openvpn openvpn Access Server

Fri, 10 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title HTTP Request Smuggling via Line-Feed Sequences in OpenVPN Access Server OpenVPN Access Server: OpenVPN Access Server: HTTP request smuggling via bare line-feed sequences in HTTP headers
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}

threat_severity

Moderate


Thu, 09 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title HTTP Request Smuggling via Line-Feed Sequences in OpenVPN Access Server

Wed, 08 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Description OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
Weaknesses CWE-444
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N'}


Subscriptions

Openvpn Openvpn Access Server
cve-icon MITRE

Status: PUBLISHED

Assigner: OpenVPN

Published:

Updated: 2026-07-08T16:30:47.077Z

Reserved: 2025-04-02T07:56:08.672Z

Link: CVE-2025-3110

cve-icon Vulnrichment

Updated: 2026-07-08T16:30:04.925Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-08T16:19:38Z

Links: CVE-2025-3110 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:15:06Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')