CVE-2025-15497: Openvpn

Low severity, CVSS 3.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service

Affected products

  • Openvpn Openvpn: from 2.7_alpha1, up to and including 2.7_rc5

Published 2026-01-30. Last modified 2026-06-17.