Blame

33411b flichtenheld 2026-07-08 14:09:48 1
# CVE-2026-13122 - Server assert via malformed auth-token with external-auth
b144c8 David Sommerseth 2026-06-23 22:27:31 2
f6f51b flichtenheld 2026-07-23 14:51:51 3
OpenVPN 2.6 and 2.7 allow remote attackers to cause a denial of service via a malformed authentication token when the server is configured with `auth-gen-token` using the `external-auth` keyword. When the token length is invalid, the server triggers a reachable assertion.
4
5
Affects versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. This is fixed in versions 2.6.21 and 2.7.5.
33411b flichtenheld 2026-07-08 14:09:48 6
7
CVE Record: [CVE-2026-13122](https://www.cve.org/CVERecord?id=CVE-2026-13122)
8
9
Github:
10
* [OpenVPN/openvpn-private-issues#118](https://github.com/OpenVPN/openvpn-private-issues/issues/118)
11
12
Release notes:
13
* [openvpn-2.7.5](https://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026)
14
* [openvpn-2.6.21](https://community.openvpn.net/ReleaseHistory#openvpn-2621-released-1-july-2026)
15
16
Reported-By: Haiyang Huang (huanghaiyang83@gmail.com)