Vendor scorecard
OpenVPN
OpenVPN security disclosure record — CVE volume, CVSS severity mix and product-category breakdown, sourced from the NIST NVD.
CPE: openvpn
Product families
1
Open in latest
29
Inferred — see methodology
Last disclosure
Jul 30, 2026
01
Product categories
1 trackedCVE volume, severity mix and the inferred latest shipping version per category.
| Category | CVEs | Volume | Severity mix | Open | Inferred latest |
|---|---|---|---|---|---|
| OpenVPN / Access ServerSecure Remote Access / VPNopenvpn, openvpn_access_server, connect | 19 | 29 | 12.11HIGH |
02
Recent CVEs
12 shownMost recently published, newest first. Each ID links to its NVD record.
| CVE | Severity | CVSS | Summary | Published |
|---|---|---|---|---|
| CVE-2026-13379(opens NVD record) | Critical | 9.1 | The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process | Jul 30, 2026 |
| CVE-2026-13117(opens NVD record) | High | 8.1 | An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage | Jul 30, 2026 |
| CVE-2026-12996(opens NVD record) | High | 8.1 | A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry | Jul 30, 2026 |
| CVE-2026-12932(opens NVD record) | High | 8.1 | A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets | Jul 30, 2026 |
| CVE-2026-11771(opens NVD record) | High | 7.5 | OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server | Jul 30, 2026 |
| CVE-2026-12139(opens NVD record) | Medium | 4.4 | Tanium addressed an information disclosure vulnerability in Connect. | Jul 21, 2026 |
| CVE-2025-3110(opens NVD record) | High | 7.5 | OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy | Jul 8, 2026 |
| CVE-2026-13122(opens NVD record) | Medium | 5.3 | OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled | Jul 6, 2026 |
| CVE-2026-13698(opens NVD record) | High | 7.5 | A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service | Jul 6, 2026 |
| CVE-2026-11604(opens NVD record) | Medium | 6.5 | An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service). | Jun 10, 2026 |
| CVE-2026-40215(opens NVD record) | High | 7.4 | A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion. | Jun 8, 2026 |
| CVE-2026-35058(opens NVD record) | Medium | 6.5 | Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet. | Jun 8, 2026 |
19 CVEs · 1 product families