# CVE-2026-13122 - Server assert via malformed auth-token with external-auth OpenVPN 2.6 and 2.7 allow remote attackers to cause a denial of service via a malformed authentication token when the server is configured with `auth-gen-token` using the `external-auth` keyword. When the token length is invalid, the server triggers a reachable assertion. Affects versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. This is fixed in versions 2.6.21 and 2.7.5. CVE Record: [CVE-2026-13122](https://www.cve.org/CVERecord?id=CVE-2026-13122) Github: * [OpenVPN/openvpn-private-issues#118](https://github.com/OpenVPN/openvpn-private-issues/issues/118) Release notes: * [openvpn-2.7.5](https://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026) * [openvpn-2.6.21](https://community.openvpn.net/ReleaseHistory#openvpn-2621-released-1-july-2026) Reported-By: Haiyang Huang (huanghaiyang83@gmail.com)
