OpenVPN 2.7.8 -- Released 7 October 2026

The OpenVPN community project team is proud to release OpenVPN 2.7.8. This is a bugfix release fixing several security issues.

For details see Changes.rst

Security fixes:

  • Check for NULL-Bytes in certificate subjects - refuse all such certificates now as "invalid" (CVE-2026-84790).

    (Bug reported by Vivek Parikh, tracked in Github: OpenVPN/openvpn-private-issues#163)

  • TLS handshake with tls-crypt-v2: do not try to add a wrapped client key if no key material is available (client bug in response to an ill-behaving server).

    (No CVE assigned as "a malicious server can stop the client from working properly" is not considered a CVE-worthy security issue according to the CRA guidelines)

  • options: fix unsigned underflow when clearing domain_search_list (CVE-2026-88964)

    (Bug reported and fix contributed by Cole Munz, tracked in Github: OpenVPN/openvpn-private-issues#178)

  • win32: stop cmd.exe from expanding variables in quoted arguments (CVE-2026-84256)

    (Bug reported by Darren Carreras, tracked in Github: OpenVPN/openvpn-private-issues#176)

User-visible Changes:

  • Certificate validation is now stricter regarding NULL bytes in strings (see above). This might break existing installations if such certificates exist and OpenSSL builds are used. mbedTLS builds always rejected this.

  • On a certificate with duplicate fields (multiple CN, for example) OpenSSL builds would use the last one, mbedTLS builds use the first one - changed in the mbedTLS build so behaviour is identical.

Bugfixes:

  • DCO: remove installed iroutes at client exit time, not at delayed multi instance cleanup time - otherwise there is a race with reconnecting clients, possibly ending up having "no iroutes installed in the system at all". Bug reported by OpenVPN Inc Access Server team.

  • DCO Linux: fix remaining races between synchronous netlink operations and incoming asynchronous notifications, by adding a second netlink socket and strictly separating sync/async operations.

  • Client: refuse incoming pushed option combination of epoch data format with non-AEAD ciphers (restart session instead of aborting with a fatal error).

  • DCO (Linux and Windows): on failures to set up a new peer or install key materials for a peer, do not exit OpenVPN with a fatal error. Instead, signal the error up the call-chain and restart the (multi) instance.

    The handshake is inherently racy when a peer is removed kernel-side due to transport errors or timeouts, and userland does not yet know this and wants to, for example, install new keys. This is fatal for the particular client instance, but must not end the whole server process.

  • DCO: stop fetching peer stats during client disconnect The intention of the original code was to ensure reported counters are always correct, but it did not work (because at query time, the peer in kernel is already gone, so we only got an error message) - and very inefficiently so (because we queried all the peers all the time). End-of-session final counter values will be implemented properly by a followup patch leveraging counters piggybacked on the kernel's "DEL_PEER" notification message.

  • p2mp server: improve handling of mbuf lists in the face of broadcast or multicast traffic, and fix a bug on client exit that could lead to a server queue deadlock in very particular scenarios.

Windows MSI changes since 2.7.7-I001:

  • Update included dco-win driver to v2.8.13
    • CVE-2026-105390 — a locking flaw allowed a local user with access to the driver's device to cause a system deadlock and denial of service, hanging the host until it was power-cycled.
    • Performance improvements by moving to multi-core data processing. See Release Notes for details.
  • Update included OpenSSL to 3.6.5
  • Update included Easy-RSA to 3.2.7
Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.7.8-I001-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.7.8-I001-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.7.8-I001-x86.msi
Source archive file GnuPG Signature openvpn-2.7.8.tar.gz

For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.

OpenVPN 2.6.23 -- Released 23 September 2026

The OpenVPN community project team is proud to release OpenVPN 2.6.23. This is a bugfix release fixing several security issues.

Important

After 2.6.22 release the support status of OpenVPN 2.6 changed from "Full Support" to "Old Stable Support". This means that we might not provide Windows installer downloads of future 2.6.x releases.

For details see Changes.rst

Security fixes:

  • ssl: do not trust the peer's request to resend the wrapped client key

    Tracked in Github: OpenVPN/openvpn-private-issues#181

  • reliability layer: avoid unbounded reliable TLS timeout, and ignore acks for packets that cannot be outstanding (CVE-2026-84732)

    Both reliability layer bugs found by Mark Bregman (Fox-IT), tracked in Github: OpenVPN/openvpn-private-issues#161

  • improve on check_session_buf_not_used(), catch possible double-free in the lame duck case (CVE-2026-84471)

    Bug reported by Andreas Gabriel Berbescu, tracked in Github: OpenVPN/openvpn-private-issues#157, and by Haruki Oyama (Waseda University), tracked in OpenVPN/openvpn-private-issues#132

  • windows: fix CreateProcess() command line quoting for characters that are special to cmd.exe, where a combination of validation script plus rogue CA could lead to misbehavior (CVE-2026-84256)

    Bug found by Clouditera Security, tracked in Github: OpenVPN/openvpn-private-issues#159

  • windows: fix tapctl to always call netsh.exe with full path (as we do elsewhere) (CVE-2026-84226)

    Bug found by BreachX Zero Day Labs (using Typhon AI Mil v2), tracked in Github: OpenVPN/openvpn-private-issues#164

  • windows: don't use NULL DACL with system objects, namely the --service exit event and the netsh.exe guard semaphore. The old approach was prone to a local DoS where one user could interfere with other users' openvpn processes by blocking the netsh semaphore or sending events. This only affects setups not using the iservice, or using the automatic service to start/stop openvpn (CVE-2026-82312)

    Bug found by DEBRAJ BASAK, tracked in Github: OpenVPN/openvpn-private-issues#167

  • dhcp (windows): fix off-by-one in write_dhcp_search_str() temp buffer guard - suitable DHCP options could lead to a single-byte overflow of a temp buffer (CVE-2026-81738)

    Bug found by Andre Kropp (Nexory) and ChinhNguyen, tracked in Github: OpenVPN/openvpn-private-issues#165

  • openvpnserv (windows): detect and refuse sibling dirs in CheckConfigPath() (CVE-2026-81830)

    Bug found by Harshit Varu, tracked in Github: OpenVPN/openvpn-private-issues#166

Windows MSI changes since 2.6.22-I001:

  • Update included dco-win driver to v1.3.4
    • CVE-2026-105390 — a locking flaw allowed a local user with access to the driver's device to cause a system deadlock and denial of service, hanging the host until it was power-cycled.
  • Update included OpenSSL to 3.6.5
Windows 64-bit MSI installer GnuPG Signature OpenVPN-2.6.23-I002-amd64.msi
Windows ARM64 MSI installer GnuPG Signature OpenVPN-2.6.23-I002-arm64.msi
Windows 32-bit MSI installer GnuPG Signature OpenVPN-2.6.23-I002-x86.msi
Source archive file GnuPG Signature openvpn-2.6.23.tar.gz

Full Release History

0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9