OpenVPN — свободная реализация технологии виртуальной частной сети (VPN) с открытым исходным кодом для создания зашифрованных каналoв типа точка-точка или сервер-клиенты между компьютерами.
Релизный цикл, информация об уязвимостях
График релизов
Количество 254
CVE-2026-40215
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 throug ...
CVE-2026-40215
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.
CVE-2026-35058
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.
CVE-2026-35058
Improper validation of packet length during tls-crypt-v2 key extractio ...
CVE-2026-35058
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.
CVE-2026-40215
A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.
BDU:2026-07108
Уязвимость функции tls_crypt_v2_extract_client_key() программного обеспечения OpenVPN, позволяющая нарушителю вызвать отказ в обслуживании
SUSE-SU-2026:0831-1
Security update for openvpn
openSUSE-SU-2026:20137-1
Security update for openvpn
GHSA-xv5w-q5wq-r3c3
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2026-40215 A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 throug ... | CVSS3: 7.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-40215 A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion. | CVSS3: 7.4 | 0% Низкий | 3 месяца назад | |
CVE-2026-35058 Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-35058 Improper validation of packet length during tls-crypt-v2 key extractio ... | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-35058 Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet. | CVSS3: 6.5 | 1% Низкий | 3 месяца назад | |
CVE-2026-40215 A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
BDU:2026-07108 Уязвимость функции tls_crypt_v2_extract_client_key() программного обеспечения OpenVPN, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.7 | 1% Низкий | 5 месяцев назад | |
SUSE-SU-2026:0831-1 Security update for openvpn | 1% Низкий | 6 месяцев назад | ||
openSUSE-SU-2026:20137-1 Security update for openvpn | 1% Низкий | 8 месяцев назад | ||
GHSA-xv5w-q5wq-r3c3 Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client | CVSS3: 7.5 | 1% Низкий | 10 месяцев назад |
Уязвимостей на страницу