CVE-2026-13379
The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:N/SA:H
- EPSS probability
- 0.34%
- CWE
- CWE-142, CWE-125
- Published
- 2026-07-30
- Last modified
- 2026-07-30
Affected products
- OpenVPN OpenVPN
Weakness type
Related vulnerabilities
- CVE-2025-61962 — In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334...
- CVE-2025-1774 — Logs manipulation in BotSense