CVE-2026-13698: Medium severity OpenVPN OpenVPN vulnerability
A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/openvpnto a version that resolves this vulnerability.Fixed in 2.6.14-0+deb12u2Fixed in 2.6.14-1+deb13u3Fixed in 2.7.5-1 - Upgrade
Upgrade
OpenVPNto a version that resolves this vulnerability.Fixed in 2.7.4 - Compensating control
Mitigate exposure by restricting remote access to OpenVPN management/network endpoints so only trusted clients can connect.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13698?
CVE-2026-13698 has a risk score of 23, indicating a significant security vulnerability.
What versions of OpenVPN are affected by CVE-2026-13698?
CVE-2026-13698 affects OpenVPN versions 2.5.0 through 2.5.11, 2.6.0 through 2.6.20, and 2.7_alpha1 through 2.7.4.
How do I fix CVE-2026-13698?
To remediate CVE-2026-13698, update OpenVPN to the latest version beyond 2.7.4.
What type of attack does CVE-2026-13698 allow?
CVE-2026-13698 allows remote attackers to potentially cause a denial of service through a memory leak.
What triggers the vulnerability in CVE-2026-13698?
The vulnerability in CVE-2026-13698 can be triggered by remote attackers using a valid tls-crypt-v2 client key.