Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-63650

Опубликовано: 14 авг. 2026
Источник: debian

Описание

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

Пакеты

ПакетСтатусВерсия исправленияРелизТип
openvpnunfixedpackage

Примечания

  • https://community.openvpn.net/Security%20Announcements/CVE-2026-63650

  • Debian does not use the mbedTLS backend, ENABLE_CRYPTO_MBEDTLS not set

Связанные уязвимости

ubuntu
20 дней назад

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

CVSS3: 3.1
redhat
20 дней назад

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

nvd
20 дней назад

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field

github
20 дней назад

OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field