Remote DNS State Pollution in OpenVPN Windows Interactive Service
CVE-2026-13379

5.1MEDIUM

Key Information:

Vendor

Openvpn

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-13379?

The Windows interactive service in OpenVPN versions 2.7_alpha1 through 2.7.4 is susceptible to a vulnerability that allows remote attackers to manipulate DNS resolutions. By exploiting crafted search domains during the disconnection process, attackers can not only cause persistent DNS state pollution but may also induce a service crash. This could lead to a disruption in connectivity and a potential compromise of sensitive data. It is crucial for users of affected versions to patch their installations promptly to mitigate these risks.

Affected Version(s)

OpenVPN Windows 2.7_alpha1 <= 2.7.4

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.