CVE-2025-12106: Critical severity OpenVPN OpenVPN vulnerability
Published Dec 1, 2025
·Updated
Insufficient argument validation in OpenVPN 2.7alpha1 through 2.7rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
Affected Software
9 affected components
OpenVPN OpenVPN>=2.7_alpha1<=2.7_rc1
OpenVPN OpenVPN=2.6.13
OpenVPN OpenVPN=2.7-alpha1
OpenVPN OpenVPN=2.7-alpha2
OpenVPN OpenVPN=2.7-alpha3
OpenVPN OpenVPN=2.7-beta1
OpenVPN OpenVPN=2.7-beta2
OpenVPN OpenVPN=2.7-beta3
OpenVPN OpenVPN=2.7-rc1
Event History
Dec 1, 2025
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
DescriptionWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12106?
CVE-2025-12106 is considered a high severity vulnerability due to its potential to allow an attacker to exploit heap buffer over-read vulnerabilities.
2
How do I fix CVE-2025-12106?
To fix CVE-2025-12106, upgrade to a version of OpenVPN later than 2.7_rc1 that addresses this vulnerability.
3
What versions of OpenVPN are affected by CVE-2025-12106?
OpenVPN versions 2.7_alpha1 through 2.7_rc1 are affected by CVE-2025-12106.
4
What type of vulnerability is CVE-2025-12106?
CVE-2025-12106 is categorized as a heap buffer over-read vulnerability related to insufficient argument validation.
5
Can CVE-2025-12106 be exploited remotely?
Yes, an attacker can exploit CVE-2025-12106 remotely by sending specially crafted data to trigger the vulnerability.