← Back

Openvpn

openvpn

Vendor: Openvpn • 50 CVEs

CVEs (50)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openvpn
1Openvpn
Aug 5, 2026
Jul 30, 2026
5.1 MEDIUM· v4
9.1 CRITICAL· v3
N/A· v2
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process
1Openvpn
1Openvpn
Aug 5, 2026
Jul 30, 2026
6.0 MEDIUM· v4
8.1 HIGH· v3
N/A· v2
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or m...Show more
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakageShow less
2Debian
Openvpn
2Debian Linux
Openvpn
Aug 5, 2026
Jul 30, 2026
6.0 MEDIUM· v4
8.1 HIGH· v3
N/A· v2
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or...Show more
A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiryShow less
1Openvpn
1Openvpn
Aug 5, 2026
Jul 30, 2026
7.1 HIGH· v4
8.1 HIGH· v3
N/A· v2
A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets
1Openvpn
1Openvpn
Aug 5, 2026
Jul 30, 2026
7.0 HIGH· v4
7.5 HIGH· v3
N/A· v2
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious...Show more
OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy serverShow less
1Openvpn
1Openvpn
Jul 9, 2026
Jul 6, 2026
5.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enable...Show more
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabledShow less
1Openvpn
1Openvpn
Jul 9, 2026
Jul 6, 2026
6.0 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
1Openvpn
1Openvpn
Aug 11, 2026
Jun 10, 2026
5.6 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption...Show more
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).Show less
1Openvpn
1Openvpn
Aug 11, 2026
Jun 8, 2026
6.1 MEDIUM· v4
7.4 HIGH· v3
N/A· v2
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.
1Openvpn
1Openvpn
Aug 11, 2026
Jun 8, 2026
6.9 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of servi...Show more
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.Show less
1Openvpn
1Openvpn
Jun 17, 2026
Dec 3, 2025
4.6 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection res...Show more
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating clientShow less
1Openvpn
1Openvpn
Jun 17, 2026
Dec 3, 2025
1.3 LOW· v4
5.5 MEDIUM· v3
N/A· v2
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of servi...Show more
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.Show less
1Openvpn
1Openvpn
Jun 17, 2026
Dec 1, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
1Openvpn
1Openvpn
Jun 17, 2026
Apr 3, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges
1Openvpn
1Openvpn
Jun 17, 2026
Apr 2, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
1Openvpn
1Openvpn
Jun 17, 2026
Jan 6, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
1Openvpn
1Openvpn
Jun 17, 2026
Jul 8, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
1Openvpn
1Openvpn
Jun 17, 2026
Jul 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive s...Show more
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.Show less
1Openvpn
1Openvpn
Jun 17, 2026
Jul 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.
1Openvpn
1Openvpn
Jun 17, 2026
Jul 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.