This page lists all security announcements made by the OpenVPN project.
# Announcements
+
* [CVE-2025-15497 - in epoch key handling (an authenticated remote system can send a valid OpenVPN data packet that triggers an endge case where a too-strict check would trigger an ASSERT(), exiting OpenVPN)](./CVE-2025-15497) (Jan 2026)
* [CVE-2025-13751 - Windows/interactive service: fix erroneous exit on error that could be used by a local Windows users to achieve a local denial-of-service](./CVE-2025-13751) (Nov 2025)