Blame
| ef2447 | uddr | 2026-09-03 14:33:00 | 1 | ## OpenVPN 2.7.7 -- Released 3 September 2026 |
| 2 | The OpenVPN community project team is proud to release OpenVPN 2.7.7. This is a bugfix release fixing |
|||
| 3 | many security issues. |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 4 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 5 | For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.7.7/Changes.rst) |
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 6 | |
| 7 | Security fixes: |
|||
| 8 | ||||
| ef2447 | uddr | 2026-09-03 14:33:00 | 9 | - reliability layer: avoid unbounded reliable TLS timeout, and ignore acks |
| 10 | for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732)) |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 11 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 12 | Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in |
| 13 | Github: OpenVPN/openvpn-private-issues#161 |
|||
| 8b6955 | flichtenheld | 2026-08-05 14:28:29 | 14 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 15 | - windows: fix `CreateProcess()` command line quoting for characters that |
| 16 | are special to `cmd.exe`, where a combination of validation script plus |
|||
| 17 | rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256)) |
|||
| 8b6955 | flichtenheld | 2026-08-05 14:28:29 | 18 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 19 | Bug found by Clouditera Security, tracked in Github: |
| 20 | OpenVPN/openvpn-private-issues#159 |
|||
| 6e939a | flichtenheld | 2026-07-01 14:44:18 | 21 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 22 | - windows: fix `tapctl` to always call `netsh.exe` with full path |
| 23 | (as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226)) |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 24 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 25 | Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in |
| 26 | Github: OpenVPN/openvpn-private-issues#164 |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 27 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 28 | - windows: don't use NULL DACL with system objects, namely the `--service` |
| 29 | exit event and the `netsh.exe` guard semaphore. The old approach was |
|||
| 30 | prone to a local DoS where one user could interfere with other users' |
|||
| 31 | openvpn processes by blocking the netsh semaphore or sending events. |
|||
| 32 | This only affects setups not using the iservice, or using the automatic |
|||
| 33 | service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312)) |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 34 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 35 | Bug found by DEBRAJ BASAK, tracked in Github: |
| 36 | OpenVPN/openvpn-private-issues#167 |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 37 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 38 | - openvpnserv (windows): pass correct NRPT domains size - when IDN domains |
| 39 | with UTF8 encoding were involved, a buffer overread could be achieved |
|||
| 40 | ([CVE-2026-78221](https://www.cve.org/CVERecord?id=CVE-2026-78221)) |
|||
| 41 | ||||
| 42 | Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github: |
|||
| 43 | OpenVPN/openvpn-private-issues#162 |
|||
| 44 | ||||
| 45 | - openvpnserv (windows): don't allow '/' in config paths. The APIs windows |
|||
| 46 | uses for path validation do not handle '/' as path separator, while the |
|||
| 47 | file open APIs do, so this could be used to circumvent our config path |
|||
| 48 | validation, leading to openvpn.exe starting a user-controlled config file |
|||
| 49 | even if administratively not allowed ([CVE-2026-78043](https://www.cve.org/CVERecord?id=CVE-2026-78043)) |
|||
| 50 | ||||
| 51 | Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github: |
|||
| 52 | OpenVPN/openvpn-private-issues#162 |
|||
| 53 | ||||
| 54 | - dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer |
|||
| 55 | guard - suitable DHCP options could lead to a single-byte overflow of a |
|||
| 56 | temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738)) |
|||
| 57 | ||||
| 58 | Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github: |
|||
| 59 | OpenVPN/openvpn-private-issues#165 |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 60 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 61 | - linux netlink: validate netlink replies against the request |
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 62 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 63 | Suggested by Joshua Rogers as a security improvement, tracked in Github: |
| 64 | OpenVPN/openvpn-private-issues#9 |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 65 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 66 | - openvpnserv (windows): fix off-by-one on input validation |
| 67 | (discovered while fixing CVE-2026-78221) |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 68 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 69 | - openvpnserv (windows): harden `CheckConfigPath()` a bit more |
| 70 | (another improvement while working on CVE-2026-78043) |
|||
| 71 | ||||
| 72 | User-visible Changes: |
|||
| 73 | ||||
| 74 | - when using EPOCH data channel format, reduce the number of future keys |
|||
| 75 | from 16 to 4 - the previous calculation was wrong, and 4 spare keys are |
|||
| 76 | sufficient for 100+ Gbit/s links. This means less log spam in userland |
|||
| 77 | and fewer resources used in in-kernel implementations. |
|||
| 8b6955 | flichtenheld | 2026-08-05 14:28:29 | 78 | |
| 79 | Bugfixes: |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 80 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 81 | - work around a pubkey-handling bug in mbedTLS 4.1.0 and 4.2.0 |
| 82 | (supposedly fixed in 4.3.0) |
|||
| 83 | ||||
| 84 | - multi: don't let stale-routes-check delete permanent routes - |
|||
| 85 | `--stale-routes-check` did not only delete dynamic cached routes, but |
|||
| 86 | also routes installed by `--iroute` and `--ifconfig-push`. Fixed by |
|||
| 87 | introducing route flags and restraining the check on them |
|||
| 88 | (Github: [OpenVPN/openvpn#1063](https://github.com/OpenVPN/openvpn/issues/1063)) |
|||
| 89 | ||||
| 90 | - ssl: do not queue control ciphertext while a packet is still queued |
|||
| 91 | (fixes problems in TCP p2p handshake when both sides try to handshake |
|||
| 92 | at the same time) |
|||
| 93 | (Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089)) |
|||
| 94 | ||||
| 95 | - reenable xmit_hold when using p2p tcp-server and tls-server - in TCP |
|||
| 96 | server mode the server is not expected to initiate the TLS handshake. |
|||
| 97 | This was introduced by the multisocket code checking the wrong variable |
|||
| 98 | for socket protocol |
|||
| 99 | (Github: [OpenVPN/openvpn#1089](https://github.com/OpenVPN/openvpn/issues/1089)) |
|||
| 100 | ||||
| 101 | - clinat: do not adjust UDP checksum if zero (as per RFC768) |
|||
| 102 | (Github: [OpenVPN/openvpn#1037](https://github.com/OpenVPN/openvpn/issues/1037)) |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 103 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 104 | - openssl: avoid resetting the HMAC key on every packet |
| 105 | (Github: [OpenVPN/openvpn#1088](https://github.com/OpenVPN/openvpn/issues/1088)) |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 106 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 107 | - openvpnserv (windows): fix log lines format string - interface names with |
| 108 | international characters printed in some error messages need to be |
|||
| 109 | converted from UTF8 to UCS16 first. |
|||
| 39396b | flichtenheld | 2026-07-01 13:37:52 | 110 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 111 | - fix format string specifier for size_t (%zu) |
| 6e939a | flichtenheld | 2026-07-01 14:44:18 | 112 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 113 | - fix test_misc compile issues with -Werror |
| c8181c | flichtenheld | 2026-06-10 16:39:29 | 114 | |
| ef2447 | uddr | 2026-09-03 14:33:00 | 115 | Windows MSI changes since 2.7.6-I001: |
| 116 | * Update included dco-win driver to v2.8.7 |
|||
| 778b33 | uddr | 2026-09-07 09:55:08 | 117 | * peer: fix use-after-free in multipeer peer table handling (Github: [OpenVPN/ovpn-dco-win#140](https://github.com/OpenVPN/ovpn-dco-win/pull/140))([CVE-2026-82325](https://www.cve.org/CVERecord?id=CVE-2026-82325)) |
| 118 | * inf: set the device security descriptor in the hardware key (Github: [OpenVPN/ovpn-dco-win#139](https://github.com/OpenVPN/ovpn-dco-win/pull/139)) |
|||
| 21a0aa | flichtenheld | 2026-03-31 15:00:25 | 119 | |
| 99ee06 | flichtenheld | 2025-07-31 19:24:29 | 120 | | | | | |
| 121 | |-|-|-| |
|||
| ef2447 | uddr | 2026-09-03 14:33:00 | 122 | |**Windows 64-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi.asc)|[OpenVPN-2.7.7-I001-amd64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-amd64.msi)| |
| 123 | |**Windows ARM64 MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi.asc)|[OpenVPN-2.7.7-I001-arm64.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-arm64.msi)| |
|||
| 124 | |**Windows 32-bit MSI installer**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi.asc)|[OpenVPN-2.7.7-I001-x86.msi](https://swupdate.openvpn.org/community/releases/OpenVPN-2.7.7-I001-x86.msi)| |
|||
| 125 | |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz.asc)|[openvpn-2.7.7.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.7.7.tar.gz)| |
|||
| 99ee06 | flichtenheld | 2025-07-31 19:24:29 | 126 | |
| 21a0aa | flichtenheld | 2026-03-31 15:00:25 | 127 | For Community-maintained packages for Linux distributions see [OpenVPN Software Repositories](/Pages/OpenVPN%20software%20repos). |
| 687bbf | novaflash | 2025-06-20 17:21:18 | 128 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 129 | ## OpenVPN 2.6.23 -- Released 23 September 2026 |
| 130 | The OpenVPN community project team is proud to release OpenVPN 2.6.23. This is a bugfix release fixing |
|||
| 8a81ee | flichtenheld | 2026-07-01 14:35:40 | 131 | several security issues. |
| 23ddda | flichtenheld | 2026-02-04 14:22:30 | 132 | |
| d2738c | flichtenheld | 2026-08-06 15:19:11 | 133 | > [!IMPORTANT] |
| 557498 | flichtenheld | 2026-09-23 16:01:44 | 134 | > After 2.6.22 release the [support status](../Pages/Supported%20versions) of OpenVPN 2.6 changed from "Full Support" to "Old Stable Support". |
| 135 | > This means that we do not provide Windows installer downloads of future 2.6.x releases. |
|||
| d2738c | flichtenheld | 2026-08-06 15:19:11 | 136 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 137 | For details see [Changes.rst](https://github.com/OpenVPN/openvpn/blob/v2.6.23/Changes.rst) |
| 485d55 | flichtenheld | 2026-02-04 18:03:20 | 138 | |
| a92ca4 | uddr | 2026-04-22 15:02:45 | 139 | Security fixes: |
| 23ddda | flichtenheld | 2026-02-04 14:22:30 | 140 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 141 | - ssl: do not trust the peer's request to resend the wrapped client key |
| 8a81ee | flichtenheld | 2026-07-01 14:35:40 | 142 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 143 | Tracked in Github: OpenVPN/openvpn-private-issues#181 |
| 6e939a | flichtenheld | 2026-07-01 14:44:18 | 144 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 145 | - reliability layer: avoid unbounded reliable TLS timeout, and ignore acks |
| 146 | for packets that cannot be outstanding ([CVE-2026-84732](https://www.cve.org/CVERecord?id=CVE-2026-84732)) |
|||
| 8a81ee | flichtenheld | 2026-07-01 14:35:40 | 147 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 148 | Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in |
| 149 | Github: OpenVPN/openvpn-private-issues#161 |
|||
| 8a81ee | flichtenheld | 2026-07-01 14:35:40 | 150 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 151 | - improve on `check_session_buf_not_used()`, catch possible double-free in |
| 152 | the lame duck case ([CVE-2026-84471](https://www.cve.org/CVERecord?id=CVE-2026-84471)) |
|||
| 8a81ee | flichtenheld | 2026-07-01 14:35:40 | 153 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 154 | Bug reported by Andreas Gabriel Berbescu, tracked in Github: |
| 155 | OpenVPN/openvpn-private-issues#157, and by Haruki Oyama (Waseda |
|||
| 156 | University), tracked in OpenVPN/openvpn-private-issues#132 |
|||
| f8247c | flichtenheld | 2026-08-05 19:37:38 | 157 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 158 | - windows: fix `CreateProcess()` command line quoting for characters that |
| 159 | are special to `cmd.exe`, where a combination of validation script plus |
|||
| 160 | rogue CA could lead to misbehavior ([CVE-2026-84256](https://www.cve.org/CVERecord?id=CVE-2026-84256)) |
|||
| f8247c | flichtenheld | 2026-08-05 19:37:38 | 161 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 162 | Bug found by Clouditera Security, tracked in Github: |
| 163 | OpenVPN/openvpn-private-issues#159 |
|||
| f8247c | flichtenheld | 2026-08-05 19:37:38 | 164 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 165 | - windows: fix `tapctl` to always call `netsh.exe` with full path |
| 166 | (as we do elsewhere) ([CVE-2026-84226](https://www.cve.org/CVERecord?id=CVE-2026-84226)) |
|||
| 8a81ee | flichtenheld | 2026-07-01 14:35:40 | 167 | |
| 30bd51 | uddr | 2026-09-23 14:18:40 | 168 | Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in |
| 169 | Github: OpenVPN/openvpn-private-issues#164 |
|||
| 170 | ||||
| 171 | - windows: don't use NULL DACL with system objects, namely the `--service` |
|||
| 172 | exit event and the `netsh.exe` guard semaphore. The old approach was |
|||
| 173 | prone to a local DoS where one user could interfere with other users' |
|||
| 174 | openvpn processes by blocking the netsh semaphore or sending events. |
|||
| 175 | This only affects setups not using the iservice, or using the automatic |
|||
| 176 | service to start/stop openvpn ([CVE-2026-82312](https://www.cve.org/CVERecord?id=CVE-2026-82312)) |
|||
| 177 | ||||
| 178 | Bug found by DEBRAJ BASAK, tracked in Github: |
|||
| 179 | OpenVPN/openvpn-private-issues#167 |
|||
| 180 | ||||
| 181 | - dhcp (windows): fix off-by-one in `write_dhcp_search_str()` temp buffer |
|||
| 182 | guard - suitable DHCP options could lead to a single-byte overflow of a |
|||
| 183 | temp buffer ([CVE-2026-81738](https://www.cve.org/CVERecord?id=CVE-2026-81738)) |
|||
| 184 | ||||
| 185 | Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github: |
|||
| 186 | OpenVPN/openvpn-private-issues#165 |
|||
| 187 | ||||
| 188 | - openvpnserv (windows): detect and refuse sibling dirs in |
|||
| 189 | `CheckConfigPath()` ([CVE-2026-81830](https://www.cve.org/CVERecord?id=CVE-2026-81830)) |
|||
| 190 | ||||
| 191 | Bug found by Harshit Varu, tracked in Github: |
|||
| 192 | OpenVPN/openvpn-private-issues#166 |
|||
| 8a81ee | flichtenheld | 2026-07-01 14:35:40 | 193 | |
| 4b4a8b | uddr | 2025-06-20 13:43:39 | 194 | | | | | |
| 195 | |-|-|-| |
|||
| 30bd51 | uddr | 2026-09-23 14:18:40 | 196 | |**Source archive file**|[GnuPG Signature](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz.asc)|[openvpn-2.6.23.tar.gz](https://swupdate.openvpn.org/community/releases/openvpn-2.6.23.tar.gz)| |
| 4b4a8b | uddr | 2025-06-20 13:43:39 | 197 | |
| ecf3c7 | uddr | 2025-11-17 14:47:15 | 198 | #### [Full Release History](https://community.openvpn.net/ReleaseHistory) |
