logo

Pre-Auth RCE Risk: OpenSSL Patches High-Severity Stack Overflow (CVE-2025-15467)

ID: 4e5b0e2c-9b35-5bd7-9dfa-3d0368b15982

STIX ID: report--4e5b0e2c-9b35-5bd7-9dfa-3d0368b15982

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-04-23

Author: Ddos

...
...

**OpenSSL security update addressing multiple vulnerabilities:** The advisory details a high-severity stack buffer overflow in CMS AuthEnvelopedData processing (CVE-2025-15467) that can be triggered without authentication and may allow remote code execution or denial-of-service, a moderate PKCS#12 PBMAC1 validation issue (CVE-2025-11187), and several low-severity flaws; maintainers provide specific patched OpenSSL versions for affected branches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.