OpenVPN 2.7.7 -- Released 3 September 2026

The OpenVPN community project team is proud to release OpenVPN 2.7.7. This is a bugfix release fixing many security issues.

For details see Changes.rst

Security fixes:

  • reliability layer: avoid unbounded reliable TLS timeout, and ignore acks for packets that cannot be outstanding (CVE-2026-84732)

    Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in Github: OpenVPN/openvpn-private-issues#161

  • windows: fix CreateProcess() command line quoting for characters that are special to cmd.exe, where a combination of validation script plus rogue CA could lead to misbehavior (CVE-2026-84256)

    Bug found by Clouditera Security, tracked in Github: OpenVPN/openvpn-private-issues#159

  • windows: fix tapctl to always call netsh.exe with full path (as we do elsewhere) (CVE-2026-84226)

    Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in Github: OpenVPN/openvpn-private-issues#164

  • windows: don't use NULL DACL with system objects, namely the --service exit event and the netsh.exe guard semaphore. The old approach was prone to a local DoS where one user could interfere with other users' openvpn processes by blocking the netsh semaphore or sending events. This only affects setups not using the iservice, or using the automatic service to start/stop openvpn (CVE-2026-82312)

    Bug found by DEBRAJ BASAK, tracked in Github: OpenVPN/openvpn-private-issues#167

  • openvpnserv (windows): pass correct NRPT domains size - when IDN domains with UTF8 encoding were involved, a buffer overread could be achieved (CVE-2026-78221)

    Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github: OpenVPN/openvpn-private-issues#162

  • openvpnserv (windows): don't allow '/' in config paths. The APIs windows uses for path validation do not handle '/' as path separator, while the file open APIs do, so this could be used to circumvent our config path validation, leading to openvpn.exe starting a user-controlled config file even if administratively not allowed (CVE-2026-78043)

    Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), in Github: OpenVPN/openvpn-private-issues#162

  • dhcp (windows): fix off-by-one in write_dhcp_search_str() temp buffer guard - suitable DHCP options could lead to a single-byte overflow of a temp buffer (CVE-2026-81738)

    Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github: OpenVPN/openvpn-private-issues#165

  • linux netlink: validate netlink replies against the request

    Suggested by Joshua Rogers as a security improvement, tracked in Github: OpenVPN/openvpn-private-issues#9

  • openvpnserv (windows): fix off-by-one on input validation (discovered while fixing CVE-2026-78221)

  • openvpnserv (windows): harden CheckConfigPath() a bit more (another improvement while working on CVE-2026-78043)

User-visible Changes:

  • when using EPOCH data channel format, reduce the number of future keys from 16 to 4 - the previous calculation was wrong, and 4 spare keys are sufficient for 100+ Gbit/s links. This means less log spam in userland and fewer resources used in in-kernel implementations.

Bugfixes:

  • work around a pubkey-handling bug in mbedTLS 4.1.0 and 4.2.0 (supposedly fixed in 4.3.0)

  • multi: don't let stale-routes-check delete permanent routes - --stale-routes-check did not only delete dynamic cached routes, but also routes installed by --iroute and --ifconfig-push. Fixed by introducing route flags and restraining the check on them (Github: OpenVPN/openvpn#1063)

  • ssl: do not queue control ciphertext while a packet is still queued (fixes problems in TCP p2p handshake when both sides try to handshake at the same time) (Github: OpenVPN/openvpn#1089)

  • reenable xmit_hold when using p2p tcp-server and tls-server - in TCP server mode the server is not expected to initiate the TLS handshake. This was introduced by the multisocket code checking the wrong variable for socket protocol (Github: OpenVPN/openvpn#1089)

  • clinat: do not adjust UDP checksum if zero (as per RFC768) (Github: OpenVPN/openvpn#1037)

  • openssl: avoid resetting the HMAC key on every packet (Github: OpenVPN/openvpn#1088)

  • openvpnserv (windows): fix log lines format string - interface names with international characters printed in some error messages need to be converted from UTF8 to UCS16 first.

  • fix format string specifier for size_t (%zu)

  • fix test_misc compile issues with -Werror

Windows MSI changes since 2.7.6-I001:

Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.7.7-I001-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.7.7-I001-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.7.7-I001-x86.msi
Source archive file GnuPG Signature openvpn-2.7.7.tar.gz

For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.

OpenVPN 2.6.22 -- Released 5 August 2026

The OpenVPN community project team is proud to release OpenVPN 2.6.22. This is a bugfix release fixing several security issues.

Important

After this release the support status of OpenVPN 2.6 changes from "Full Support" to "Old Stable Support" This means that we might not provide Windows installer downloads of future 2.6.x releases. Please upgrade to OpenVPN 2.7.

For details see Changes.rst

Security fixes:

  • openvpnserv (windows): better scrutinize command line passed in from the control socket to openvpn. This would lead to circumventing admin restrictions on allowed openvpn config directories (but never to "read files the user has no permissions for") (CVE-2026-63649)

    Bug found by 章鱼哥 (www.aipyaipy.com)

  • dco: make key state desync recoverable

    This was reported as a "with suitable timing, a key-update de-sync between OpenVPN and the kernel could trigger an ASSERT()", and was initially handled as security report. It turned out to be not exploitable, but the state machine was not very robust and so the opportunity was used to improve the code.

    Bug found by 章鱼哥 (www.aipyaipy.com)

Bugfixes:

  • refuse incoming HARD RESET packets with a sequence ID != 0 (this is basically making an OpenVPN server ignore and log a "should never happen" client-side misbehaviour, which could lead to TLS handshake establishment failures in p2p TLS setups)

  • correct minimum packet length check for 802.1q tagged packets (Github: OpenVPN/openvpn#1044).

    This was also reported (twice) as a security bug, as technically OpenVPN with --client-nat would read and write up to 4 bytes "after the end of the packet" - but due to the OpenVPN packet buffer layouts, which are always full-frame-sized this is fully safe and has no adverse consequences.

Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.6.22-I001-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.6.22-I001-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.6.22-I001-x86.msi
Source archive file GnuPG Signature openvpn-2.6.22.tar.gz

For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.

Full Release History

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9