OpenVPN 2.7_rc4 -- Released 17 December 2025
The OpenVPN community project team is proud to release OpenVPN 2.7_rc4. This is the fourth release candidate for the feature release 2.7.0.
Important bug fixes since 2.7_rc3:
- Windows interactive service: do not configure adapter DNS if there are no search-domains but there are resolve-domains (which get resolved via NRPT rules) - GH: OpenVPN/openvpn#473
- improve documentation and error messages for a number of deprecated options
- improve documentation for not-really-deprecated-yet
--ns-cert-type - Windows IPv4 configuration with netsh.exe: ensure addresses are added with "store=active" (ensure proper cleanup) - GH: OpenVPN/openvpn#915
- Windows: set UTF8 code page in openvpn.exe manifest, to make cert/key loading work again for files with non-ASCII characters in their file name (GH: OpenVPN/openvpn#920)
- tun.c: unify read_tun()/write_tun() functions for all BSD platforms
- more type conversion related cleanups
- add NULL check before freeaddrinfo() call, which might lead to a crash on OpenBSD (GH: OpenVPN/openvpn#930)
- add NULL check to mbedtls handling of external and inline certificates
- add check for auth none / cipher none on FreeBSD DCO
- add CAP_SYS_NICE to positive list in Linux systemd unit files (GH: OpenVPN/openvpn#834)
- drop mbedtls 2.x support (which is end of life, and work on mbedtls 4 is much simplified by not having to take care of 2.x compat as well)
- PUSH_UPDATE: bugfix for the client side where split/continued messages (due to large number of "route" statements) would not correctly handle the full set of routes. Add unit test. (GH: OpenVPN/openvpn#925)
- new unit test module for mbuf handling
- deprecate --fast-io option (it got partially broken by the multisocket implementation, and the benefits of the existing implementation did not outweigh the extra code complexity to make it work again)
- change the ssl_ctx in struct tls_options to be a pointer - this is a shared data structure between various contexts, but previously it was shallow-copied, leading to needless CRL reloading - and when working on implementing the new OpenSSL CRL API, to segfaults (the existing code works, as these new APIs are not used yet).
For a list of all changes see the git log.
Highlights of 2.7 include:
- Multi-socket support for servers -- Handle multiple addresses/ports/protocols within one server
- Improved Client support for DNS options
- Client implementations for Linux/BSD/macOS, included with the default install
- New client implementation for Windows, adding support for features like split DNS and DNSSEC
- Architectural improvements on Windows
- The
block-localflag is now enforced with WFP filters - Windows network adapters are now generated on demand
- Windows automatic service now runs as an unpriviledged user
- Support for server mode in win-dco driver
- Note: Support for the wintun driver has been removed. win-dco is now the default, tap-windows6 is the fallback solution for use-cases not covered by win-dco.
- The
- Improved data channel
- Enforcement of AES-GCM usage limit
- Epoch data keys and packet format
- Support for new upstream DCO Linux kernel module
- This release supports the new
ovpnDCO Linux kernel module which will be available in future upstream Linux kernel releases. Backports of the new module to current kernels are available via the ovpn-backports project.
- This release supports the new
- Client-side support for new
PUSH_UPDATEcontrol-channel message- This allows servers to send updates to options like routing and DNS config without triggering a reconnect.
- PUSH_UPDATE server support (minimal)
- New management interface commands
push-update-broadandpush-update-cidto send PUSH_UPDATE option updates.
- New management interface commands
- TLS 1.3 support with bleeding-edge mbedTLS versions
- Two new environment variables have been introduced to communicate desired default gateway redirection to plugins like Network Manager.
- Support for Epoch data channel on Windows, using the win-dco driver (2.8.0+)
- "Recursive Routing" check is now more granular, and will only drop packets-in-tunnel if destination IP, protocol and port matches with those needed to reach the VPN server.
- COPYING: license details only relevant to our Windows installers have been updated and moved to the openvpn-build repo
For details see Changes.rst
Windows MSI changes since 2.7_rc3:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.60.0.0
- Update copyright year in About dialog
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc4-I012-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.7_rc4-I012-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.7_rc4-I012-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.7_rc4.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories. Note that the Fedora Copr repositories have been moved to the @OpenVPN group account and that there are new repositories available on openSUSE Buildservice.
OpenVPN 2.6.17 -- Released 28 November 2025
The OpenVPN community project team is proud to release OpenVPN 2.6.17. This is a bugfix release containing one security fix.
For details see Changes.rst
Security fixes:
- CVE-2025-13751: Windows/interactive service: fix erroneous exit on error that could be used by a local Windows users to achieve a local denial-of-service
Bug fixes:
- Windows/interactive service: improve service pipe robustness against file access races (uuid) and access by unauthorized processes (ACL).
- upgrade bundled build instruction (vcpkg and patch) for pkcs11-helper to 1.31, fixing a parser bug
Windows MSI changes since 2.6.16-I001:
- Built against OpenSSL 3.6.0
- Included openvpn-gui updated to 11.59.0.0
- Authorize config before opening the service pipe
- Remove dependence on pathcch.dll not in Windows 7
- Included win-dco driver updated to 2.8.0
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.6.17-I001-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.6.17-I001-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.6.17-I001-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.6.17.tar.gz |
For Community-maintained packages for Linux distributions see OpenVPN Software Repositories.
OpenVPN 2.5.9 -- Released 15 February 2023
The OpenVPN community project team is proud to release OpenVPN 2.5.9. This is a small bugfix release.
For details see Changes.rst
Windows MSI changes since 2.5.8:
- Build against OpenSSL 1.1.1t which contains several security fixes.
| Windows 64-bit MSI installer | GnuPG Signature | OpenVPN-2.5.9-I601-amd64.msi |
| Windows ARM64 MSI installer | GnuPG Signature | OpenVPN-2.5.9-I601-arm64.msi |
| Windows 32-bit MSI installer | GnuPG Signature | OpenVPN-2.5.9-I601-x86.msi |
| Source archive file | GnuPG Signature | openvpn-2.5.9.tar.gz |
