This page lists all security announcements made by the OpenVPN project.
# Announcements
+
* [CVE-2026-40215 - fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances](./CVE-2026-40215) (Apr 2026)
+
* [CVE-2026-35058 - fix server ASSERT() on receiving a suitably malformed packet with a valid tls-crypt-v2 key](./CVE-2026-35058) (Apr 2026)
* [CVE-2026-2738 - ovpn-dco-win 2.8.0 buffer overflow with AEAD using epoch data keys](./CVE-2026-2738)
* [CVE-2025-15497 - in epoch key handling (an authenticated remote system can send a valid OpenVPN data packet that triggers an endge case where a too-strict check would trigger an ASSERT(), exiting OpenVPN)](./CVE-2025-15497) (Jan 2026)
* [CVE-2025-13751 - Windows/interactive service: fix erroneous exit on error that could be used by a local Windows users to achieve a local denial-of-service](./CVE-2025-13751) (Nov 2025)