Search CVE reports


Toggle filters

1 – 10 of 61 results


CVE-2026-13379

Medium priority
Needs evaluation

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-13122

Medium priority

Some fixes available 2 of 3

OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-13698

Medium priority

Some fixes available 3 of 8

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-13117

Medium priority

Some fixes available 2 of 3

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-12996

Medium priority

Some fixes available 3 of 8

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-12932

Medium priority

Some fixes available 3 of 8

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-11771

Medium priority

Some fixes available 2 of 3

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-41070

Medium priority
Needs evaluation

openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the...

1 affected package

openvpn-auth-oauth2

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn-auth-oauth2 Needs evaluation Not in release Not in release
Show less packages

CVE-2026-40215

Medium priority

Some fixes available 4 of 8

A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-35058

Medium priority

Some fixes available 4 of 8

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a...

1 affected package

openvpn

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
openvpn Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages