CVE-2025-2704: Openvpn

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase

Affected products

  • Openvpn Openvpn: from 2.6.1, up to and including 2.6.13

Published 2025-04-02. Last modified 2026-06-17.