Commit 8cf56a

2026-07-23 15:09:13 flichtenheld: -/-
Security Announcements.md ..
@@ 3,12 3,12 @@
This page lists all security announcements made by the OpenVPN project.
# Announcements
- * [CVE-2026-13379](./CVE-2026-13379) (July 2026)
+ * [CVE-2026-13379 - Windows interactive service DNS SearchList state pollution](./CVE-2026-13379) (July 2026)
* [CVE-2026-12996 - Potential DoS and memory leak via TLS session use-after-free](./CVE-2026-12996) (July 2026)
* [CVE-2026-13117 - Heap use-after-free via incomplete guard in check_session_buf_not_used()](./CVE-2026-13117) (July 2026)
* [CVE-2026-13122 - Server assert via malformed auth-token with external-auth](./CVE-2026-13122) (July 2026)
* [CVE-2026-12932 - memory leak using --tls-crypt-v2](./CVE-2026-12932) (July 2026)
- * [CVE-2026-11771- NTLM proxy auth stack off-by-one write](./CVE-2026-11771) (July 2026)
+ * [CVE-2026-11771 - NTLM proxy auth stack off-by-one write](./CVE-2026-11771) (July 2026)
* [CVE-2026-13698 - Server memory leak via repeated tls-crypt-v2 HARD_RESET_CLIENT_V3 packets](./CVE-2026-13698) (July 2026)
* [CVE-2026-40215 - fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances](./CVE-2026-40215) (Apr 2026)
* [CVE-2026-35058 - fix server ASSERT() on receiving a suitably malformed packet with a valid tls-crypt-v2 key](./CVE-2026-35058) (Apr 2026)
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9