CVE-2025-13086
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.6
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
- EPSS probability
- 0.64%
- CWE
- CWE-940
- Published
- 2025-12-03
- Last modified
- 2026-03-13
Affected products
- OpenVPN OpenVPN
- OpenVPN OpenVPN
Weakness type
Related vulnerabilities
- CVE-2026-85085 — The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged...
- CVE-2026-78685 — Le-yan|Medical Practice Management System - Remote Code Execution
- CVE-2026-73419 — NextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
- CVE-2026-55660 — TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover
- CVE-2026-54106 — U.S. GAO EPDS and CBCA EDS network access control bypass
- CVE-2026-48745 — Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry
- CVE-2026-44894 — Netty's Default QUIC token handler accepts any client-supplied token
- CVE-2026-44698 — Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callback injection