Use-After-Free Vulnerability in OpenVPN Affecting Several Versions
CVE-2026-13117

6MEDIUM

Key Information:

Vendor

Openvpn

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-13117?

An incomplete guard in OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 can potentially allow remote authenticated peers to exploit a use-after-free condition during the TLS session promotion process. This flaw may lead to both denial of service scenarios and possible memory leakage, compromising the integrity and availability of network services.

Affected Version(s)

OpenVPN 2.6.0 <= 2.6.20

OpenVPN 2.7_alpha1 <= 2.7.4

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.