Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93p4-5c7j-q5rx

Опубликовано: 30 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 8.1

Описание

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

EPSS

Процентиль: 35%
0.00417
Низкий

7.1 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-401

Связанные уязвимости

CVSS3: 8.1
ubuntu
19 дней назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 7.5
redhat
19 дней назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 8.1
nvd
19 дней назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets

CVSS3: 8.1
debian
19 дней назад

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5 ...

suse-cvrf
7 дней назад

Security update for openvpn

EPSS

Процентиль: 35%
0.00417
Низкий

7.1 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-401