For details see [v2.7_alpha2/Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_alpha2/Changes.rst) and [v2.7_alpha1/Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7_alpha1/Changes.rst)
Windows MSI changes since 2.6.14:
-
* Includes fix for [CVE-2025-50054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50054)
+
* Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord?id=CVE-2025-50054)
* Built against OpenSSL 3.5.0
* Included openvpn-gui updated to 11.54.0.0
* Support for webauth in PLAP (Pre-Logon Access Provider) via QR code (github [openvpn-gui#687](https://github.com/OpenVPN/openvpn-gui/issues/687))
@@ 44,7 44,7 @@
Security fixes:
-
* [CVE-2025-2704](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-2704): fix possible `ASSERT()` on OpenVPN servers using `--tls-crypt-v2`
+
* [CVE-2025-2704](https://www.cve.org/CVERecord?id=CVE-2025-2704): fix possible `ASSERT()` on OpenVPN servers using `--tls-crypt-v2`
Security scope: OpenVPN servers between 2.6.1 and 2.6.13 using
`--tls-crypt-v2` can be made to abort with an `ASSERT()` message by
sending a particular combination of authenticated and malformed packets.
@@ 66,7 66,7 @@
* Disable config in menu listing if its ovpn file becomes inaccessible (github [openvpn-gui#729](https://github.com/OpenVPN/openvpn-gui/issues/729))
Note: Windows MSI was updated to I002 on June 19th. Changes in I002:
-
* Includes fix for [CVE-2025-50054](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-50054)
+
* Includes fix for [CVE-2025-50054](https://www.cve.org/CVERecord?id=CVE-2025-50054)