Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13698

Опубликовано: 06 июл. 2026
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

A flaw was found in OpenVPN. A memory leak vulnerability allows remote attackers, who possess a valid tls-crypt-v2 client key, to potentially trigger a denial of service. This can disrupt the availability of the OpenVPN service.

Отчет

Moderate: A memory leak in OpenVPN could lead to a denial of service. This vulnerability requires a valid tls-crypt-v2 client key, limiting the attack surface to authenticated remote attackers. While requiring authentication, repeated exploitation could exhaust system resources, impacting service availability on Red Hat supported OpenVPN deployments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Дополнительная информация

Статус:

Moderate

EPSS

Процентиль: 24%
0.00314
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
24 дня назад

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

CVSS3: 7.5
nvd
24 дня назад

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

CVSS3: 7.5
debian
24 дня назад

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2 ...

CVSS3: 7.5
github
24 дня назад

A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service

EPSS

Процентиль: 24%
0.00314
Низкий

4.9 Medium

CVSS3

Уязвимость CVE-2026-13698