CVE-2026-78221
An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:N/VA:H/SC:H/SI:N/SA:H
- EPSS probability
- 0.12%
- CWE
- CWE-131
- Published
- 2026-09-07
- Last modified
- 2026-09-08
Affected products
- OpenVPN OpenVPN
Weakness type
Related vulnerabilities
- CVE-2026-22590 — Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG sampleSize / fragmentsInSubmessage
- CVE-2026-69598 — Windows iSCSI Remote Code Execution Vulnerability
- CVE-2026-18743 — Popt-devel: popt-static: short realloc in poptconfigfiletostring
- CVE-2026-78002 — Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function
- CVE-2026-44254 — Wazuh: Stack Out-of-Bounds Write in remoted Decompression Path
- CVE-2026-52834 — jxl-oxide: Out-of-bounds writes due to integer overflow in jxl-grid on 32-bit platforms
- CVE-2026-75093 — sonos tract ONNX Initializer Loader tensor.rs from_raw_dt_align buffer size
- CVE-2026-70457 — rsync 3.2.3 < 3.5.0 Out-of-Bounds Write via parse_size_arg()