- EPSS 0.36%
- Veröffentlicht 14.08.2026 22:13:26
- Zuletzt bearbeitet 17.08.2026 16:17:22
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
CVE-2026-63649
- EPSS 0.33%
- Veröffentlicht 14.08.2026 22:13:21
- Zuletzt bearbeitet 17.08.2026 16:17:21
The Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that byp...
CVE-2026-12932
- EPSS 0.42%
- Veröffentlicht 30.07.2026 16:42:03
- Zuletzt bearbeitet 05.08.2026 19:38:24
A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets
CVE-2026-12996
- EPSS 0.46%
- Veröffentlicht 30.07.2026 16:38:58
- Zuletzt bearbeitet 05.08.2026 19:38:07
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry
CVE-2026-11771
- EPSS 0.38%
- Veröffentlicht 30.07.2026 16:36:41
- Zuletzt bearbeitet 05.08.2026 19:38:34
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server
CVE-2026-13117
- EPSS 0.4%
- Veröffentlicht 30.07.2026 16:32:42
- Zuletzt bearbeitet 05.08.2026 19:37:47
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage
CVE-2026-13379
- EPSS 0.34%
- Veröffentlicht 30.07.2026 16:28:19
- Zuletzt bearbeitet 05.08.2026 19:37:28
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process
CVE-2026-13122
- EPSS 0.29%
- Veröffentlicht 06.07.2026 14:32:29
- Zuletzt bearbeitet 09.07.2026 13:06:19
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
CVE-2026-13698
- EPSS 0.31%
- Veröffentlicht 06.07.2026 14:13:49
- Zuletzt bearbeitet 09.07.2026 13:05:30
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
CVE-2026-11604
- EPSS 0.34%
- Veröffentlicht 10.06.2026 21:04:37
- Zuletzt bearbeitet 11.08.2026 13:01:04
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, res...