Vulnerabilities (CVE)

Filtered by vendor Openvpn Subscribe
Total 71 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-3110 1 Openvpn 1 Openvpn Access Server 2026-07-10 N/A 7.5 HIGH
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
CVE-2026-13122 1 Openvpn 1 Openvpn 2026-07-09 N/A 5.3 MEDIUM
OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
CVE-2026-13698 1 Openvpn 1 Openvpn 2026-07-09 N/A 7.5 HIGH
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
CVE-2023-46850 3 Debian, Fedoraproject, Openvpn 4 Debian Linux, Fedora, Openvpn and 1 more 2026-06-23 N/A 9.8 CRITICAL
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
CVE-2026-9560 1 Openvpn 1 Connect 2026-06-17 N/A 7.8 HIGH
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
CVE-2025-50054 1 Openvpn 1 Ovpn-dco-win 2026-06-17 N/A 5.5 MEDIUM
Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash
CVE-2025-3908 2 Linux, Openvpn 2 Linux Kernel, Openvpn3linux 2026-06-17 N/A 6.2 MEDIUM
The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.
CVE-2025-2704 1 Openvpn 1 Openvpn 2026-06-17 N/A 7.5 HIGH
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
CVE-2025-13751 2 Microsoft, Openvpn 2 Windows, Openvpn 2026-06-17 N/A 5.5 MEDIUM
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.
CVE-2025-13086 1 Openvpn 1 Openvpn 2026-06-17 N/A 7.5 HIGH
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
CVE-2025-12106 1 Openvpn 1 Openvpn 2026-06-17 N/A 9.1 CRITICAL
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
CVE-2024-8474 1 Openvpn 1 Connect 2026-06-17 N/A 7.5 HIGH
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
CVE-2024-5594 1 Openvpn 1 Openvpn 2026-06-17 N/A 9.1 CRITICAL
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
CVE-2024-5198 1 Openvpn 1 Ovpn-dco-win 2026-06-17 N/A 3.3 LOW
OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
CVE-2024-4877 2 Microsoft, Openvpn 2 Windows, Openvpn 2026-06-17 N/A 8.8 HIGH
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges
CVE-2024-28882 1 Openvpn 1 Openvpn 2026-06-17 N/A 4.3 MEDIUM
OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
CVE-2024-27903 1 Openvpn 1 Openvpn 2026-06-17 N/A 9.8 CRITICAL
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
CVE-2024-27459 1 Openvpn 1 Openvpn 2026-06-17 N/A 7.8 HIGH
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.
CVE-2024-24974 1 Openvpn 1 Openvpn 2026-06-17 N/A 7.5 HIGH
The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.
CVE-2024-1305 1 Openvpn 1 Tap-windows6 2026-06-17 N/A 9.8 CRITICAL
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space