Memory leak in OpenVPN Server - CVE-2026-12932
Published: July 2, 2026 / Updated: July 28, 2026
OpenVPN Server
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a memory leak in tls-crypt-v2 client key handling when processing tls-crypt-v2 client keys. A remote attacker can send a sequence of crafted inputs to cause a denial of service.
The issue can lead to an out-of-memory condition before the server crashes.