Home

Description

Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) endpoint servers to inject arbitrary web script or HTML via the RelayState parameter

PUBLISHED Reserved 2025-06-11 | Published 2025-10-27 | Updated 2025-10-27 | Assigner OpenVPN

Problem types

CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

2.14.0 (semver)
affected

References

openvpn.net/as-docs/as-3-0-release-notes.html

cve.org (CVE-2025-50055)

nvd.nist.gov (CVE-2025-50055)

Download JSON