Out-of-bounds write in OpenVPN Server - CVE-2026-11771
Published: July 2, 2026 / Updated: July 28, 2026
OpenVPN Server
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in NTLMv2 proxy responses when parsing response data. A remote attacker can send specially crafted response data to cause a denial of service.
The advisory describes the overrun as limited to one byte.