Improper validation of source IP addresses in OpenVPN...
Moderate severity
Unreviewed
Published
Dec 3, 2025
to the GitHub Advisory Database
•
Updated Jan 30, 2026
Description
Published by the National Vulnerability Database
Dec 3, 2025
Published to the GitHub Advisory Database
Dec 3, 2025
Last updated
Jan 30, 2026
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
References