PatchSiren

OpenVPN CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OpenVPN CVE published 2026-07-30

CVE-2026-13379

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 is vulnerable to a remote attack that can cause persistent DNS state pollution or a service crash. This occurs when a crafted search domain is provided during the disconnection process. The vulnerability has a CVSS score of 5.1 and a medium severity. Affected product deployments should be reviewed for exposure, and owners should be assign [truncated]

MEDIUM OpenVPN CVE published 2026-07-30

CVE-2026-13117

The CVE-2026-13117 vulnerability affects OpenVPN, specifically versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. An incomplete guard allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage. OpenVPN users and administrators should be aware of this vulnerability and take steps to patch or mitigate it t [truncated]

MEDIUM OpenVPN CVE published 2026-07-30

CVE-2026-12996

A use-after-free vulnerability in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry. This vulnerability affects OpenVPN deployments, particularly those using versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. The vulnerability's impact includ [truncated]

HIGH OpenVPN CVE published 2026-07-30

CVE-2026-11771

OpenVPN versions 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 are vulnerable to an off-by-one buffer write issue related to NTLM proxy authentication. This could potentially cause a crash via a crafted NTLM response from a malicious proxy server. The CVSS score for this vulnerability is 7, indicating high severity. OpenVPN has addressed this issue in versions 2.6.21 and 2.7.5. Users and administrator [truncated]

MEDIUM Openvpn CVE published 2026-07-06

CVE-2026-13122

CVE-2026-13122 is a denial-of-service vulnerability in OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. The vulnerability allows remote attackers to trigger a reachable assertion when external-auth is enabled via a malformed authentication token. This issue can cause a denial of service, potentially disrupting VPN services. Users of affected OpenVPN versions should apply patches or miti [truncated]

MEDIUM OpenVPN CVE published 2026-07-06

CVE-2026-13698

A memory leak vulnerability was discovered in OpenVPN versions 2.5.0 through 2.5.11, 2.6.0 through 2.6.20, and 2.7_alpha1 through 2.7.4. This vulnerability allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service. The vulnerability is caused by a memory leak in OpenVPN, which can be exploited by remote attackers to potentially cause a denial of service. Users o [truncated]

MEDIUM OpenVPN CVE published 2026-06-10

CVE-2026-11604

CVE-2026-11604 is a medium-severity vulnerability in OpenVPN ovpn-dco-win versions 2.0.0 through 2.8.3. An incorrect buffer size calculation in the epoch key generator allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service). The CVSS score for this vulnerability is 5.6, indicating a m [truncated]

MEDIUM OpenVPN CVE published 2026-06-08

CVE-2026-40215

CVE-2026-40215 is a medium-severity vulnerability in OpenVPN, allowing remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion. The vulnerability affects OpenVPN versions 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1.

MEDIUM OpenVPN CVE published 2026-06-08

CVE-2026-35058

CVE-2026-35058 is a medium-severity vulnerability in OpenVPN, affecting versions 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1. The vulnerability is caused by improper validation of packet length during tls-crypt-v2 key extraction, allowing authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet. The CVSS score for this vulnerability is 6.9, in [truncated]

MEDIUM Openvpn CVE published 2019-07-09

CVE-2016-6329

CVE-2016-6329 is a confidentiality issue in OpenVPN tied to the use of 64-bit block ciphers. NVD describes it as making it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, with an HTTP-over-OpenVPN Blowfish-CBC example of the Sweet32 class of attacks. The NVD record lists affected OpenVPN versions up to 2.3.14 when configured with a vuln [truncated]