CVE-2025-12106: Openvpn

Critical severity, CVSS 9.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses

Affected products

  • Openvpn Openvpn: version 2.6.13 only; version 2.7 only

Published 2025-12-01. Last modified 2026-09-26.