OpenVPN Connect
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in OpenVPN Connect.
By the Year
In 2026 there have been 0 vulnerabilities in OpenVPN Connect. Last year, in 2025 Connect had 1 security vulnerability published. Right now, Connect is on track to have less security vulnerabilities in 2026 than it did last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 1 | 0.00 |
| 2024 | 2 | 7.80 |
| 2023 | 1 | 5.90 |
| 2022 | 0 | 0.00 |
| 2021 | 2 | 7.45 |
It may take a day or so for new Connect vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent OpenVPN Connect Security Vulnerabilities
OpenVPN Connect <3.5.0: Config Profile Private Key leaked in logs
CVE-2024-8474
- January 06, 2025
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
OpenVPN Connect 3.03.4.3 Node.js LPE via ELECTRON_RUN_AS_NODE
CVE-2023-7245
- February 20, 2024
The nodejs framework in OpenVPN Connect 3.0 through 3.4.3 (Windows)/3.4.7 (macOS) was not properly configured, which allows a local user to execute arbitrary code within the nodejs process context via the ELECTRON_RUN_AS_NODE environment variable
OpenVPN Connect v3.0-3.4.6 MacOS LCE via DYLD_INSERT_LIBRARIES
CVE-2023-7224
7.8 - High
- January 08, 2024
OpenVPN Connect version 3.0 through 3.4.6 on macOS allows local users to execute code in external third party libraries using the DYLD_INSERT_LIBRARIES environment variable
Code Injection
OpenVPN Connect <3.4.0 MI-MITM Credential Leakage
CVE-2022-3761
5.9 - Medium
- October 17, 2023
OpenVPN Connect versions before 3.4.0.4506 (macOS) and OpenVPN Connect before 3.4.0.3100 (Windows) allows man-in-the-middle attackers to intercept configuration profile download requests which contains the users credentials
Improper Certificate Validation
OpenVPN Connect 3.2.0 through 3.3.0
CVE-2021-3613
7.8 - High
- July 02, 2021
OpenVPN Connect 3.2.0 through 3.3.0 allows local users to load arbitrary dynamic loadable libraries via an OpenSSL configuration file if present, which allows the user to run arbitrary code with the same privilege level as the main OpenVPN process (OpenVPNConnect.exe).
DLL preloading
OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access
CVE-2020-15075
7.1 - High
- March 30, 2021
OpenVPN Connect installer for macOS version 3.2.6 and older may corrupt system critical files it should not have access via symlinks in /tmp.
insecure temporary file
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for OpenVPN Connect or by OpenVPN? Click the Watch button to subscribe.