Input validation error in OpenVPN Server - CVE-2026-13122
Published: July 2, 2026 / Updated: July 28, 2026
OpenVPN Server
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in auth-token handling when processing a suitably malformed auth-token. A remote attacker can send a specially crafted auth-token to cause a denial of service.
Only servers with --auth-gen-token external-auth enabled are vulnerable.