I hope this is the right place to ask, and that someone can help me. Since Proxmox is based on KVM/QEMU, I’d like to know whether PVE 8 and PVE 9 are affected by CVE-2025-11234.
So no, Proxmox VE is not affected by that issue, unless you use custom args (which is limited to root@pam) and define your own VNC websocket via the QEMU commandline directly.