---
id: CVE-2025-8095
title: >-
  The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge
  platform
summary: "The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. \_It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications. \_OECH1 encodings should be conside…"
severity: none
cwe:
  - CWE-257
published: '2026-04-14'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8095'
references:
  - url: >-
      https://community.progress.com/s/article/Unintended-Use-of-OECH1-for-Password-Secrets-Protection
    label: security@progress.com
tags:
  - nvd
epss: 0.00216
epssPercentile: 0.10854
ingestedAt: '2026-09-30T22:27:27.754Z'
---

## Overview

The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as cryptographically weak and unsuitable for stored encodings and enterprise applications.  OECH1 encodings should be considered exploitable and immediately replaced by any other supported prefix encoding, all of which are based on symmetric encryption.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
