CVE-2025-13086: Openvpn
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
Affected products
- Openvpn Openvpn: from 2.6.0, before 2.6.16 (fixed in 2.6.16); version 2.7 only
Published 2025-12-03. Last modified 2026-09-25.