# Introduction This page lists all security announcements made by the OpenVPN project. # Announcements * [CVE-2026-84732 - Unbounded reliable TLS timeout and acks for non-outstanding packets](./CVE-2026-84732) (September 2026) * [CVE-2026-84471 - Possible double-free in check_session_buf_not_used() lame duck handling](./CVE-2026-84471) (September 2026) * [CVE-2026-84256 - Windows CreateProcess() command line quoting bypass via cmd.exe metacharacters](./CVE-2026-84256) (September 2026) * [CVE-2026-84226 - Windows tapctl binary planting via netsh.exe called without full path](./CVE-2026-84226) (September 2026) * [CVE-2026-82325 - Windows dco-win use-after-free in multipeer peer table handling](./CVE-2026-82325) (September 2026) * [CVE-2026-82312 - Windows local DoS via NULL DACL on service exit event and netsh guard semaphore](./CVE-2026-82312) (September 2026) * [CVE-2026-81830 - Windows openvpnserv config path validation bypass via sibling directories](./CVE-2026-81830) (September 2026) * [CVE-2026-81738 - Windows single-byte overflow in write_dhcp_search_str() temp buffer](./CVE-2026-81738) (September 2026) * [CVE-2026-78221 - Windows openvpnserv buffer overread via UTF8 IDN NRPT domains](./CVE-2026-78221) (September 2026) * [CVE-2026-78043 - Windows openvpnserv config path validation bypass using '/' separator](./CVE-2026-78043) (September 2026) * [CVE-2026-63650 - mbedTLS backend ignores x509-username-field](./CVE-2026-63650) (August 2026) * [CVE-2026-63649 - Windows interactive service arbitrary config load bypass](./CVE-2026-63649) (August 2026) * [CVE-2026-13379 - Windows interactive service DNS SearchList state pollution](./CVE-2026-13379) (July 2026) * [CVE-2026-12996 - Potential DoS and memory leak via TLS session use-after-free](./CVE-2026-12996) (July 2026) * [CVE-2026-13117 - Heap use-after-free via incomplete guard in check_session_buf_not_used()](./CVE-2026-13117) (July 2026) * [CVE-2026-13122 - Server assert via malformed auth-token with external-auth](./CVE-2026-13122) (July 2026) * [CVE-2026-12932 - memory leak using --tls-crypt-v2](./CVE-2026-12932) (July 2026) * [CVE-2026-11771 - NTLM proxy auth stack off-by-one write](./CVE-2026-11771) (July 2026) * [CVE-2026-13698 - Server memory leak via repeated tls-crypt-v2 HARD_RESET_CLIENT_V3 packets](./CVE-2026-13698) (July 2026) * [CVE-2026-40215 - fix race condition in TLS handshake that could lead to leaking of packet data from a previous handshake under specific circumstances](./CVE-2026-40215) (Apr 2026) * [CVE-2026-35058 - fix server ASSERT() on receiving a suitably malformed packet with a valid tls-crypt-v2 key](./CVE-2026-35058) (Apr 2026) * [CVE-2026-2738 - ovpn-dco-win 2.8.0 buffer overflow with AEAD using epoch data keys](./CVE-2026-2738) * [CVE-2025-15497 - in epoch key handling (an authenticated remote system can send a valid OpenVPN data packet that triggers an endge case where a too-strict check would trigger an ASSERT(), exiting OpenVPN)](./CVE-2025-15497) (Jan 2026) * [CVE-2025-13751 - Windows/interactive service: fix erroneous exit on error that could be used by a local Windows users to achieve a local denial-of-service](./CVE-2025-13751) (Nov 2025) * [CVE-2025-13086 - HMAC verification check: fix incorrect memcmp() call](./CVE-2025-13086) (Nov 2025) * [CVE-2025-12106 - IPv6 address parsing: fix buffer overread on invalid input](./CVE-2025-12106) (Nov 2025) * [CVE-2025-10680 - Suscepticle script injection via --dns-updown script hoook](./CVE-2025-10680) (Oct 2025) * [CVE-2025-50054 - Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier](./CVE-2025-50054) (June 2025) * [CVE-2025-3908 - OpenVPN 3 Linux, openvpn3-admin init-config follows symlink](./CVE-2025-3908) (June 2025) * [CVE-2025-2704 - OpenVPN 2.6.1 through 2.6.13 DoS with dynamic tls-crypt-v2](./CVE-2025-2704) (April 2025) * [CVE-2024-28882: OpenVPN in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session](./CVE-2024-28882) (June 2024) * [CVE-2024-5594: control channel: refuse control channel messages with non-printable characters in them](./CVE-2024-5594) (June 2024) * [CVE-2024-4877: Windows: A malicious process may spoof the interactive service and potentially impersonate a local user](./CVE-2024-4877) (June 2024) * [CVE-2024-27459: Windows: fix a possible stack overflow in the interactive service component which might lead to a local privilege escalation](./CVE-2024-27459) (Mar 2024) * [CVE-2024-24974: Windows: disallow access to the interactive service pipe from remote computers](./CVE-2024-24974) (Mar 2024) * [CVE-2024-27903: Windows: disallow loading of plugins from untrusted installation paths, which could be used to attack openvpn.exe via a malicious plugin](./CVE-2024-27903) (Mar 2024) * [CVE-2024-1305: Windows TAP driver: Fix potential integer overflow in TapSharedSendPacket](./CVE-2024-1305) (Mar 2024) * [CVE-2023-7235: OpenVPN 2.x GUI privilege escalation possible if installed outside default installation path on Windows](./CVE-2023-7235) (Feb 2024) * [CVE-2023-6247: PKCS#7 parser in OpenVPN 3 Core Library can result in NULL-dereference](./CVE-2023-6247) (Feb 2024) * [CVE-2023-46850: Incorrect use of send buffer can cause memory to be sent to peer](./CVE-2023-46850) (Nov 2023) * [CVE-2023-46849: Use of --fragment option can lead to a division by zero error which can be fatal](./CVE-2023-46849) (Nov 2023) * [TunnelCrack: LocalNet and ServerIP attacks on insecure networks](./TunnelCrack) (Oct 2023) * [CVE-2022-0547: Potential authentication by-pass with multiple deferred authentication plug-ins](./CVE-2022-0547) * [CVE-2021-3547: OpenVPN 3 Core library 3.6 and 3.6.1 possible certificate authentication bypass with --verify-x509-name](./CVE-2021-3547) * [CVE-2021-3606: OpenVPN 2.5.2 (Windows only) may load an external OpenSSL configuration file](./CVE-2021-3606) * [CVE-2020-15078: partial information leak upon unauthorized client reconnection](./CVE-2020-15078) (Apr 2021) * [DUHK attack: ANSI X9.31 RNG and Don't Use Hard-coded Keys](./DUHKattack) (Oct 2017) * [Code execution and Privilege escalation problems with NSIS installers](./NSISBug1125) (Sep 2017) * [CVE-2017-12166: out of bounds write in key-method 1](./CVE-2017-12166) (Sep 2017) * [Unquoted service paths in OpenVPN 2.4 Windows installers](./UnquotedServicePathIn24WindowsInstallers) * [Vulnerabilities fixed in OpenVPN 2.3.17 and 2.4.3](./VulnerabilitiesFixedInOpenVPN243) (June 2017) * [Quarkslab and Cryptography Engineering audits](./QuarkslabAndCryptographyEngineerAudits) (May 2017) * [Linux kernel, UDP packets and MSG_PEEK - CVE-2016-10229](./CVE-2016-10229) (April 2017) * [OpenVPN and SWEET32](./SWEET32) (Aug 2016) * [Tap-windows6 buffer overflow vulnerability](./TapWindows6BufferOverflowVulnerability) (May 2016) * [Vulnerabilities fixed in OpenSSL 1.0.1m](./VulnerabilitiesFixedInOpenSSL1_0_1m) (Mar 2015) * [Security announcement: The FREAK vulnerability](./SecurityAnnouncement-FREAK) (Mar 2015) * [Security announcement: critical denial of service vulnerability - CVE-2014-8104](./SecurityAnnouncement-97597e732b) (Nov 2014) * [Vulnerabilities fixed in OpenSSL 1.0.1j](./VulnerabilitiesFixedInOpenSSL1_0_1j) (Oct 2014) * [Vulnerabilities fixed in OpenSSL 1.0.1i](./VulnerabilitiesFixedInOpenSSL1_0_1i) (Aug 2014) * [OpenSSL CCS Injection Vulnerability and OpenVPN - CVE-2014-0224](./CCSInjection) (Jun 2014) * [OpenSSL 'Heartbleed' vulnerability and OpenVPN](./heartbleed) (Apr 2014) * [TLS Triple Handshake Vulnerability and OpenVPN](./TLSTripleHandshakeVulnerabilityAndOpenVPN) (Mar 2013) * [Security announcement: use of non-constant-time memcmp in HMAC comparison in openvpn_decrypt - CVE-2013-2061](./SecurityAnnouncement-f375aa67cc) (Mar 2013)
