Tools

Why Serv-U is not affected by CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232

This article explains why Serv-U is not affected by CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232.

First published date

12/18/2025 9:07 PM

Last published date

12/22/2025 4:02 PM

Overview

In 2025, the National Institute of Standards and Technology (NIST) published a security bulletin about CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232. 

NVD - CVE-2025-9230 - An application trying to decrypt CMS messages encrypted using password-based encryption can trigger an out-of-bounds read and write.  

NVD - CVE-2025-9231 - A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 algorithm implementation on 64-bit ARM platforms. 

NVD - CVE-2025-9232 - An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_proxy' environment variable is set, and the host portion of the authority component of the HTTP URL is an IPv6 address. 

Product section

Serv-U Managed File Transfer & Serv-U FTP Server

Cause

CVE-2025-9230, CVE-2025-9231and CVE-2025-9232.

Resolution

Serv-U is not impacted by CVE-2025-9230, CVE-2025-9231, and CVE-2025-9232 due to the following reasons: 

  • CVE-2025-9230 - Serv-U code base does not use the CMS password decrypt-related API.

  • CVE-2025-9231 - Serv-U does not use SM2 algorithm.

  • CVE-2025-9232  Serv-U does not use OpenSSL HTTP client APIs.