Blame

21859f Samuli Seppänen 2025-03-26 06:50:15 1
# Introduction 
2
3
This page lists all security announcements made by the OpenVPN project.
4
af2235 uddr 2025-11-18 08:49:31 5
# Announcements
8b52c4 uddr 2026-09-03 15:16:04 6
* [CVE-2026-84732 - Unbounded reliable TLS timeout and acks for non-outstanding packets](./CVE-2026-84732) (September 2026)
1b5c68 uddr 2026-09-23 14:47:53 7
* [CVE-2026-84471 - Possible double-free in check_session_buf_not_used() lame duck handling](./CVE-2026-84471) (September 2026)
8b52c4 uddr 2026-09-03 15:16:04 8
* [CVE-2026-84256 - Windows CreateProcess() command line quoting bypass via cmd.exe metacharacters](./CVE-2026-84256) (September 2026)
9
* [CVE-2026-84226 - Windows tapctl binary planting via netsh.exe called without full path](./CVE-2026-84226) (September 2026)
1e6afc uddr 2026-09-07 10:01:55 10
* [CVE-2026-82325 - Windows dco-win use-after-free in multipeer peer table handling](./CVE-2026-82325) (September 2026)
8b52c4 uddr 2026-09-03 15:16:04 11
* [CVE-2026-82312 - Windows local DoS via NULL DACL on service exit event and netsh guard semaphore](./CVE-2026-82312) (September 2026)
1b5c68 uddr 2026-09-23 14:47:53 12
* [CVE-2026-81830 - Windows openvpnserv config path validation bypass via sibling directories](./CVE-2026-81830) (September 2026)
8b52c4 uddr 2026-09-03 15:16:04 13
* [CVE-2026-81738 - Windows single-byte overflow in write_dhcp_search_str() temp buffer](./CVE-2026-81738) (September 2026)
14
* [CVE-2026-78221 - Windows openvpnserv buffer overread via UTF8 IDN NRPT domains](./CVE-2026-78221) (September 2026)
15
* [CVE-2026-78043 - Windows openvpnserv config path validation bypass using '/' separator](./CVE-2026-78043) (September 2026)
f9a7d5 flichtenheld 2026-08-06 11:59:46 16
* [CVE-2026-63650 - mbedTLS backend ignores x509-username-field](./CVE-2026-63650) (August 2026)
17
* [CVE-2026-63649 - Windows interactive service arbitrary config load bypass](./CVE-2026-63649) (August 2026)
8cf56a flichtenheld 2026-07-23 15:09:13 18
* [CVE-2026-13379 - Windows interactive service DNS SearchList state pollution](./CVE-2026-13379) (July 2026)
93205b flichtenheld 2026-07-23 14:38:52 19
* [CVE-2026-12996 - Potential DoS and memory leak via TLS session use-after-free](./CVE-2026-12996) (July 2026)
db3f1e flichtenheld 2026-07-08 14:12:12 20
* [CVE-2026-13117 - Heap use-after-free via incomplete guard in check_session_buf_not_used()](./CVE-2026-13117) (July 2026)
21
* [CVE-2026-13122 - Server assert via malformed auth-token with external-auth](./CVE-2026-13122) (July 2026)
5cc65b flichtenheld 2026-07-23 14:13:38 22
* [CVE-2026-12932 - memory leak using --tls-crypt-v2](./CVE-2026-12932) (July 2026)
8cf56a flichtenheld 2026-07-23 15:09:13 23
* [CVE-2026-11771 - NTLM proxy auth stack off-by-one write](./CVE-2026-11771) (July 2026)
9e8105 flichtenheld 2026-07-08 14:14:56 24
* [CVE-2026-13698 - Server memory leak via repeated tls-crypt-v2 HARD_RESET_CLIENT_V3 packets](./CVE-2026-13698) (July 2026)
9a5767 uddr 2026-04-22 19:37:20 25
* [CVE-2026-40215 - fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances](./CVE-2026-40215) (Apr 2026)
26
* [CVE-2026-35058 - fix server ASSERT() on receiving a suitably malformed packet with a valid tls-crypt-v2 key](./CVE-2026-35058) (Apr 2026)
1f2895 David Sommerseth 2026-02-19 20:13:05 27
* [CVE-2026-2738 - ovpn-dco-win 2.8.0 buffer overflow with AEAD using epoch data keys](./CVE-2026-2738)
1cdf75 uddr 2026-01-15 20:18:52 28
* [CVE-2025-15497 - in epoch key handling (an authenticated remote system can send a valid OpenVPN data packet that triggers an endge case where a too-strict check would trigger an ASSERT(), exiting OpenVPN)](./CVE-2025-15497) (Jan 2026)
5e9374 uddr 2025-11-28 20:05:24 29
* [CVE-2025-13751 - Windows/interactive service: fix erroneous exit on error that could be used by a local Windows users to achieve a local denial-of-service](./CVE-2025-13751) (Nov 2025)
5f2cf4 uddr 2025-11-18 08:52:12 30
* [CVE-2025-13086 - HMAC verification check: fix incorrect memcmp() call](./CVE-2025-13086) (Nov 2025)
31
* [CVE-2025-12106 - IPv6 address parsing: fix buffer overread on invalid input](./CVE-2025-12106) (Nov 2025)
561bcf David Sommerseth 2026-02-19 12:39:25 32
* [CVE-2025-10680 - Suscepticle script injection via --dns-updown script hoook](./CVE-2025-10680) (Oct 2025)
5ba92c David Sommerseth 2025-06-20 06:52:55 33
* [CVE-2025-50054 - Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier](./CVE-2025-50054) (June 2025)
34
* [CVE-2025-3908 - OpenVPN 3 Linux, openvpn3-admin init-config follows symlink](./CVE-2025-3908) (June 2025)
556fa3 David Sommerseth 2025-10-23 12:44:26 35
* [CVE-2025-2704 - OpenVPN 2.6.1 through 2.6.13 DoS with dynamic tls-crypt-v2](./CVE-2025-2704) (April 2025)
21859f Samuli Seppänen 2025-03-26 06:50:15 36
* [CVE-2024-28882: OpenVPN in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session](./CVE-2024-28882) (June 2024)
37
* [CVE-2024-5594: control channel: refuse control channel messages with non-printable characters in them](./CVE-2024-5594) (June 2024)
38
* [CVE-2024-4877: Windows: A malicious process may spoof the interactive service and potentially impersonate a local user](./CVE-2024-4877) (June 2024)
39
* [CVE-2024-27459: Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation](./CVE-2024-27459) (Mar 2024)
40
* [CVE-2024-24974: Windows: disallow access to the interactive service pipe from remote computers](./CVE-2024-24974) (Mar 2024)
41
* [CVE-2024-27903: Windows: disallow loading of plugins from untrusted installation paths, which could be used to attack openvpn.exe via a malicious plugin](./CVE-2024-27903) (Mar 2024)
42
* [CVE-2024-1305: Windows TAP driver: Fix potential integer overflow in TapSharedSendPacket](./CVE-2024-1305) (Mar 2024)
43
* [CVE-2023-7235: OpenVPN 2.x GUI privilege escalation possible if installed outside default installation path on Windows](./CVE-2023-7235) (Feb 2024)
44
* [CVE-2023-6247: PKCS#7 parser in OpenVPN 3 Core Library can result in NULL-dereference](./CVE-2023-6247) (Feb 2024)
45
* [CVE-2023-46850: Incorrect use of send buffer can cause memory to be sent to peer](./CVE-2023-46850) (Nov 2023)
46
* [CVE-2023-46849: Use of --fragment option can lead to a division by zero error which can be fatal](./CVE-2023-46849) (Nov 2023)
47
* [TunnelCrack: LocalNet and ServerIP attacks on insecure networks](./TunnelCrack) (Oct 2023)
48
* [CVE-2022-0547: Potential authentication by-pass with multiple deferred authentication plug-ins](./CVE-2022-0547)
49
* [CVE-2021-3547: OpenVPN 3 Core library 3.6 and 3.6.1 possible certificate authentication bypass with --verify-x509-name](./CVE-2021-3547)
50
* [CVE-2021-3606: OpenVPN 2.5.2 (Windows only) may load an external OpenSSL configuration file](./CVE-2021-3606)
51
* [CVE-2020-15078: partial information leak upon unauthorized client reconnection](./CVE-2020-15078) (Apr 2021)
52
* [DUHK attack: ANSI X9.31 RNG and Don't Use Hard-coded Keys](./DUHKattack) (Oct 2017)
53
* [Code execution and Privilege escalation problems with NSIS installers](./NSISBug1125) (Sep 2017)
54
* [CVE-2017-12166: out of bounds write in key-method 1](./CVE-2017-12166) (Sep 2017)
55
* [Unquoted service paths in OpenVPN 2.4 Windows installers](./UnquotedServicePathIn24WindowsInstallers)
56
* [Vulnerabilities fixed in OpenVPN 2.3.17 and 2.4.3](./VulnerabilitiesFixedInOpenVPN243) (June 2017)
57
* [Quarkslab and Cryptography Engineering audits](./QuarkslabAndCryptographyEngineerAudits) (May 2017)
58
* [Linux kernel, UDP packets and MSG_PEEK - CVE-2016-10229](./CVE-2016-10229) (April 2017)
59
* [OpenVPN and SWEET32](./SWEET32) (Aug 2016)
60
* [Tap-windows6 buffer overflow vulnerability](./TapWindows6BufferOverflowVulnerability) (May 2016)
1cc22a Samuli Seppänen 2025-03-26 06:51:59 61
* [Vulnerabilities fixed in OpenSSL 1.0.1m](./VulnerabilitiesFixedInOpenSSL1_0_1m) (Mar 2015)
21859f Samuli Seppänen 2025-03-26 06:50:15 62
* [Security announcement: The FREAK vulnerability](./SecurityAnnouncement-FREAK) (Mar 2015)
63
* [Security announcement: critical denial of service vulnerability - CVE-2014-8104](./SecurityAnnouncement-97597e732b) (Nov 2014)
1cc22a Samuli Seppänen 2025-03-26 06:51:59 64
* [Vulnerabilities fixed in OpenSSL 1.0.1j](./VulnerabilitiesFixedInOpenSSL1_0_1j) (Oct 2014)
65
* [Vulnerabilities fixed in OpenSSL 1.0.1i](./VulnerabilitiesFixedInOpenSSL1_0_1i) (Aug 2014)
21859f Samuli Seppänen 2025-03-26 06:50:15 66
* [OpenSSL CCS Injection Vulnerability and OpenVPN - CVE-2014-0224](./CCSInjection) (Jun 2014)
67
* [OpenSSL 'Heartbleed' vulnerability and OpenVPN](./heartbleed) (Apr 2014)
68
* [TLS Triple Handshake Vulnerability and OpenVPN](./TLSTripleHandshakeVulnerabilityAndOpenVPN) (Mar 2013)
69
* [Security announcement: use of non-constant-time memcmp in HMAC comparison in openvpn_decrypt - CVE-2013-2061](./SecurityAnnouncement-f375aa67cc) (Mar 2013)