OpenVPN Open source VPN
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in any OpenVPN product.
RSS Feeds for OpenVPN security vulnerabilities
Create a CVE RSS feed including security vulnerabilities found in OpenVPN products with stack.watch. Just hit watch, then grab your custom RSS feed url.
Products by OpenVPN Sorted by Most Security Vulnerabilities since 2018
By the Year
In 2026 there have been 25 vulnerabilities in OpenVPN with an average score of 5.5 out of ten. Last year, in 2025 OpenVPN had 12 security vulnerabilities published. That is, 13 more vulnerabilities have already been reported in 2026 as compared to last year. Last year, the average CVE base score was greater by 2.63
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 25 | 5.55 |
| 2025 | 12 | 8.18 |
| 2024 | 7 | 8.23 |
| 2023 | 4 | 6.97 |
| 2022 | 4 | 8.08 |
| 2021 | 8 | 7.00 |
| 2020 | 4 | 7.50 |
| 2019 | 0 | 0.00 |
| 2018 | 2 | 7.80 |
It may take a day or so for new OpenVPN vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent OpenVPN Security Vulnerabilities
| CVE | Date | Vulnerability | Products |
|---|---|---|---|
| CVE-2026-82325 | Sep 07, 2026 |
OpenVPN ovpn-dco-win UAF (2.5.0-2.8.6) Crash via Control MsgA use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages |
|
| CVE-2026-84732 | Sep 07, 2026 |
OpenVPN <=2.7.6: ACK ID Retransmission Overflow DoSRetransmissions of ACK packet ID in OpenVPN through 2.6.22 and 2.7.6 allow remote unauthenticated attackers to cause a denial of service via crafted inputs that trigger a timeout integer overflow |
|
| CVE-2026-84256 | Sep 07, 2026 |
OpenVPN Windows Arg Parse Flaw: Auth User Cmd Exec (2.1_rc102.7.6)An argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to execute arbitrary commands via a crafted certificate subject |
|
| CVE-2026-84226 | Sep 07, 2026 |
OpenVPN Win 2.6.22 / 2.7.6 Local Auth Binary PlantingOpenVPN version 2.5.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to perform a binary planting attack during network configuration steps |
|
| CVE-2026-82312 | Sep 07, 2026 |
OpenVPN 2.0.0-2.7.6 Windows NULL DACL IPC Denial of ServiceOpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULL DACL on named IPC objects |
|
| CVE-2026-81830 | Sep 07, 2026 |
OpenVPN 2.4.0-2.6.22 Windows InterSvc FilePath Validation BypassThe Windows interactive service in OpenVPN 2.4.0 through 2.6.22 allows local authenticated users to bypass the trusted configuration directory constraint via incorrect file path validation |
|
| CVE-2026-81738 | Sep 07, 2026 |
OpenVPN 2.5.0-2.7.6 Windows OOB Write via DOMAIN-SEARCH (tap-windows6)OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries |
|
| CVE-2026-78221 | Sep 07, 2026 |
OpenVPN 2.7_alpha1-2.7.6: Buf Size Defect in WIntSrv (CVE-2026-78221)An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs. |
|
| CVE-2026-78043 | Sep 07, 2026 |
OpenVPN 2.7.*: Win Interactive Service auth bypass loads configThe Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via specially crafted paths |
|
| CVE-2026-63650 | Aug 14, 2026 |
Auth Misidentification in OpenVPN 2.712.7.5 via mbedTLSOpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field |
|
| CVE-2026-63649 | Aug 14, 2026 |
OpenVPN 2.4-2.7 Windows service bypass trusted config dir via whitelist hackThe Windows interactive service in OpenVPN 2.4.0 through 2.6.21 and 2.7_alpha1 through 2.7.5 allows local authenticated users to bypass the trusted configuration directory constraint and load arbitrary configuration files via crafted options that bypass whitelist checks |
|
| CVE-2026-12932 | Jul 30, 2026 |
OpenVPN 2.5.x-2.7.x TLS-crypt-v2 Client Key Extraction Mem Leak (remote DOS)A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets |
|
| CVE-2026-12996 | Jul 30, 2026 |
Use-After-Free in OpenVPN 2.6.0-2.6.20 & 2.7.1-2.7.4 TLSA use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry |
|
| CVE-2026-11771 | Jul 30, 2026 |
OpenVPN 2.1.0-2.6.20 / 2.7_alpha1-2.7.4 Off-by-One in NTLM Proxy AuthOpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server |
|
| CVE-2026-13117 | Jul 30, 2026 |
OpenVPN 2.6.0-2.6.20 & 2.7.1-2.7.4 UAF in TLS Session PromotionAn incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage |
|
| CVE-2026-13379 | Jul 30, 2026 |
OpenVPN v2.7 Alpha1-2.7.4 Windows Service DNS pollution (CVE202613379)The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process |
|
| CVE-2025-3110 | Jul 08, 2026 |
OpenVPN Access Server 2.7.23.1.0 HTTP Header LF Injection SmugglingOpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy |
|
| CVE-2026-13122 | Jul 06, 2026 |
OpenVPN 2.6.0-2.6.20/2.7.0-2.7.4 Remote DoS via Malformed Auth TokenOpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled |
|
| CVE-2026-13698 | Jul 06, 2026 |
OpenVPN 2.5.0-2.5.11/2.6.0-2.6.20/2.7.0-2.7.4 memory leak permits DoSA memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service |
|
| CVE-2026-11604 | Jun 10, 2026 |
Heap BOverflow via epoch key in OpenVPN ovpn-dco-win <=2.8.3An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service). |
|
| CVE-2026-40215 | Jun 08, 2026 |
OpenVPN 2.6.0-2.6.19/2.7_alpha1-2.7.1 UAF via TLS session promotionA race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion. |
|
| CVE-2026-35058 | Jun 08, 2026 |
OpenVPN 2.6.x-2.7.1 TLS-Crypt-V2 Length Validation DoSImproper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet. |
|
| CVE-2026-9560 | May 26, 2026 |
OpenVPN Connect 3.5.13.8.1 MacOS PrivEsc via IPC channelPrivilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel |
|
| CVE-2026-2738 | Feb 19, 2026 |
OpenVPN 2.8.0 Buffer Overflow in ovpndcowinversion AEAD TagBuffer overflow in ovpndcowinversion 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag appears at the end of the encrypted packet |
|
| CVE-2025-15497 | Jan 30, 2026 |
OpenVPN 2.7 Alpha to RC5 DoS via Epoch Key Slot AssertionInsufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service |
|
| CVE-2025-13086 | Dec 03, 2025 |
OpenVPN 2.6.02.7_rc1 IP Source Validation Bypass (DoS)Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client |
|
| CVE-2025-13751 | Dec 03, 2025 |
OpenVPN 2.5.0-2.7_rc2 LDoS via Interactive Service Agent on WindowsInteractive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service. |
|
| CVE-2025-12106 | Dec 01, 2025 |
OpenVPN 2.7_alpha1-rc1 IP Address Parsing Heap Over-ReadInsufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses |
|
| CVE-2025-50055 | Oct 27, 2025 |
OpenVPN Access Server 2.14.x SAML XSS via RelayState in AuthCross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) endpoint servers to inject arbitrary web script or HTML via the RelayState parameter |
|
| CVE-2025-10680 | Oct 24, 2025 |
OpenVPN 2.7_alpha1-beta1 DNS Variable Shell InjectionOpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use |
|
| CVE-2025-50054 | Jun 20, 2025 |
Buffer overflow in OpenVPN ovpn-dco-win <=1.3.0/<=2.5.8 causes local crashBuffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash |
|
| CVE-2025-3908 | May 19, 2025 |
OpenVPN 3 Linux v20-v24: Local Symlink Ownership EscalationThe configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory. |
|
| CVE-2024-4877 | Apr 03, 2025 |
Privilege Escalation via Named Pipe in OpenVPN GUI 2.4.0–2.6.10 WindowsOpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges |
|
| CVE-2025-2704 | Apr 02, 2025 |
OpenVPN 2.6.1-2.6.13 TLS-crypt-v2: Early Handshake Packet Replay DoSOpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase |
|
| CVE-2024-5198 | Jan 15, 2025 |
OpenVPN 1.1.1 local: OVPN-DC driver NULL deref crashOpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt. |
|
| CVE-2024-8474 | Jan 06, 2025 |
OpenVPN Connect <3.5.0: Config Profile Private Key leaked in logsOpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic |
|
| CVE-2024-5594 | Jan 06, 2025 |
OpenVPN <2.6.11 PushReply Sanitization Flaw Enables Log InjectionOpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs. |
|
| CVE-2024-28882 | Jul 08, 2024 |
OpenVPN 2.6.0-2.6.10: Authenticated Clients Extend Session via Exit MsgOpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session |
|
| CVE-2024-24974 | Jul 08, 2024 |
OpenVPN <=2.6.9 Remote Interactive Service Access (CVE-2024-24974)The interactive service in OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service. |
|
| CVE-2024-27459 | Jul 08, 2024 |
OpenVPN 2.6.9 Interactive Service Stack Overflow Privilege EscalationThe interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges. |
|
| CVE-2024-27903 | Jul 08, 2024 |
OpenVPN 2.6.9 Windows Plugin Directory Traversal Arbitrary PLG ExecOpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service. |
|
| CVE-2023-7235 | Feb 21, 2024 |
OpenVPN GUI pre-2.6.9 ACL flaw allows binary tamperingThe OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN binaries when using a non-standard installation path, which allows an attacker to replace binaries to run arbitrary executables. |
|
| CVE-2023-7245 | Feb 20, 2024 |
OpenVPN Connect 3.03.4.3 Node.js LPE via ELECTRON_RUN_AS_NODEThe nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable |
|
| CVE-2023-7224 | Jan 08, 2024 |
OpenVPN Connect v3.0-3.4.6 MacOS LCE via DYLD_INSERT_LIBRARIESOpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable |
|
| CVE-2023-46849 | Nov 11, 2023 |
OpenVPN 2.6.x DoS via Divide-by-zero on --fragmentUsing the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service. |
|
| CVE-2023-46850 | Nov 11, 2023 |
OpenVPN 2.6.0-2.6.6 UAF in Network Buffer -> Remote ExecUse after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer. |
|
| CVE-2022-3761 | Oct 17, 2023 |
OpenVPN Connect <3.4.0 MI-MITM Credential LeakageOpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download requests which contains the users credentials |
|
| CVE-2020-20813 | Aug 22, 2023 |
OpenVPN 2.4.7 Control Chan CVE-2020-20813 - DOS via reset pktControl Channel in OpenVPN 2.4.7 and earlier allows remote attackers to cause a denial of service via crafted reset packet. |
|
| CVE-2021-4234 | Jul 06, 2022 |
OpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sentOpenVPN Access Server 2.10 and prior versions are susceptible to resending multiple packets in a response to a reset packet sent from the client which the client again does not respond to, resulting in a limited amplification attack. |
|
| CVE-2022-33737 | Jul 06, 2022 |
The OpenVPN Access Server installer creates a log file readable for everyone, whichThe OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password |
|