Memory leak in OpenVPN Server - CVE-2026-13698
Published: July 2, 2026 / Updated: July 28, 2026
OpenVPN Server
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a memory leak in tls-crypt-v2 packet handling when processing suitable tls-crypt-v2 packets. A remote attacker can send specially crafted packets to cause a denial of service.
The issue can lead to an out-of-memory condition before the server crashes.