← Vulnerability feed

Vulnerability record · CVE-2023-25076 · published 30 March 2023

CVE-2023-25076: SNIProxy wildcard backend host buffer overflow allows code execution

SSniproxy Project · Sniproxy

SNIProxy 0.6.0-2 and the master branch mishandle wildcard backend hosts, producing a classic buffer overflow (CWE-120) when processing a crafted HTTP or TLS packet. The flaw is remotely reachable without authentication and can lead to arbitrary code execution, making it a serious risk for any exposed SNIProxy instance.

9.8 CVSS 3.1 Critical EPSS 66% · top 0.8% CWE-120 · Classic buffer overflow
9.8CVSS 3.1 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A buffer overflow vulnerability exists in the handling of wildcard backend hosts of SNIProxy 0.6.0-2 and the master branch (commit: 822bb80df9b7b345cc9eba55df74a07b498819ba). A specially crafted HTTP or TLS packet can lead to arbitrary code execution. An attacker could send a malicious packet to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, and code execution impact, plus high EPSS and a public exploit reference, warrant critical handling despite no KEV listing.

What it is

SNIProxy 0.6.0-2 and the master branch mishandle wildcard backend hosts, producing a classic buffer overflow (CWE-120) when processing a crafted HTTP or TLS packet. The flaw is remotely reachable without authentication and can lead to arbitrary code execution, making it a serious risk for any exposed SNIProxy instance.

Impact

An unauthenticated remote attacker can corrupt memory and potentially execute arbitrary code with the privileges of the SNIProxy process, gaining full control of the affected host or at least causing a crash.

Attack surface

Reached over the network by sending a specially crafted HTTP or TLS packet to the SNIProxy listener; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Not listed in CISA KEV, but EPSS is high (0.65753, 99.2nd percentile) and the Talos advisory is tagged Exploit, indicating public exploit detail exists though active exploitation is not confirmed.

What to do

  • Apply the upstream patch commit f8d9a433fe22ab2fa15c00179048ab02ae23d583 or upgrade to a fixed SNIProxy release.
  • Apply the Debian security updates DSA-5413 and the LTS announcement for packaged deployments.
  • Restrict network exposure of SNIProxy listeners to trusted sources and place them behind a filtering proxy or firewall where possible.
  • Review Talos TALOS-2023-1731 mitigation guidance and avoid wildcard backend host configurations until patched.

Detection

  • Monitor SNIProxy process crashes or restarts that coincide with inbound HTTP/TLS traffic.
  • Inspect proxy and network logs for malformed or unusually long SNI/host values targeting wildcard backend configurations.
  • Watch for unexpected child processes or outbound connections originating from the SNIProxy host.
  • Alert on repeated connection attempts to SNIProxy ports from single sources that precede a crash.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-25076 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

5.5CVE-2025-43520Apple OS kernel memory corruption via malicious appA memory corruption flaw (classic buffer overflow) in Apple's kernel was fixed across iOS, iPadOS, macOS, tvOS, visionOS and watchOS. A malicious app…KEVEPSS 0.43%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed9.8CVE-2022-37055D-Link Go-RT-AC750 router buffer overflow in cgibin hnap_mainD-Link Go-RT-AC750 firmware revisions A v101b03 and B v200b02 contain a classic buffer overflow reachable through the cgibin hnap_main handler. The f…KEVEPSS 56%analysed9.9CVE-2025-20333Cisco ASA and FTD VPN web server buffer overflow allows root RCECisco Secure Firewall ASA and FTD Software fail to properly validate user-supplied input in HTTP(S) requests to the VPN web server, causing a classic…KEVEPSS 71%analysed9.8CVE-2020-15069Sophos XG Firewall buffer overflow in HTTP/S BookmarksSophos XG Firewall 17.x through v17.5 MR12 contains a classic buffer overflow (CWE-120) reachable through the HTTP/S Bookmarks feature used for clien…KEVEPSS 11%analysed7.8CVE-2023-41064Apple ImageIO buffer overflow allows code execution via crafted imageA buffer overflow in Apple's ImageIO image processing component was fixed in iOS 16.6.1/iPadOS 16.6.1, iOS 15.7.9/iPadOS 15.7.9, macOS Monterey 12.6.…KEVEPSS 53%analysed9.8CVE-2023-33010Zyxel firewall ID processing buffer overflow allows unauthenticated RCEA classic buffer overflow (CWE-120) exists in the ID processing function of multiple Zyxel firewall firmware lines, including ATP, USG FLEX, USG20(W)…KEVEPSS 29%analysed9.8CVE-2023-33009Zyxel firewall notification function buffer overflowA buffer overflow in the notification function of multiple Zyxel firewall and VPN firmware lines (ATP, USG FLEX, USG20(W)-VPN, VPN, ZyWALL/USG) allow…KEVEPSS 28%analysed

Source: NIST National Vulnerability Database (record CVE-2023-25076), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.