
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11771 is a Denial of Service vulnerability in OpenVPN caused by an off-by-one buffer write in the NTLM proxy authentication code. A malicious proxy server can send a crafted NTLM response to trigger a crash in the OpenVPN client. Affected versions include OpenVPN 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. The vulnerability was published on July 30, 2026, with patches released on July 1, 2026 (versions 2.6.21 and 2.7.5). It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 7.0 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an off-by-one error (CWE-193) leading to a stack-based buffer overflow (CWE-121) and out-of-bounds write (CWE-787) in the NTLM proxy authentication handling code. When an OpenVPN client connects through an HTTP proxy using NTLM authentication, a malicious proxy server can return a specially crafted NTLM response that triggers the off-by-one write, corrupting stack memory and causing a process crash. Exploitation requires the attacker to control or impersonate the proxy server that the OpenVPN client is configured to use, and the client must have NTLM proxy authentication enabled — meaning passive user interaction (initiating a VPN connection) is a prerequisite (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation results in a crash of the OpenVPN client process, causing a Denial of Service that disrupts VPN connectivity for the affected user. There is no impact on confidentiality or integrity — the vulnerability is limited to availability. Because the crash affects only the client process, lateral movement or data exfiltration are not direct consequences of this vulnerability, though loss of VPN connectivity could expose users to less secure network paths (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the vulnerability as not automatable. The EPSS score is approximately 0.34–0.375%, placing it in roughly the 30th percentile for exploitation likelihood. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
openvpn) during proxy authentication phase./var/crash/ or equivalent.openvpn process; application event log entries (Windows) indicating OpenVPN process crash during connection establishment.OpenVPN has released patched versions 2.6.21 and 2.7.5, both made available on July 1, 2026, prior to the CVE's public disclosure on July 30, 2026. Users should upgrade to these versions or later immediately. As a workaround, avoid configuring OpenVPN to connect through untrusted or unverified proxy servers, and restrict NTLM proxy authentication to trusted proxy infrastructure only via network controls. Linux distribution packages (Debian, Ubuntu USN-8540-1, SUSE SUSE-SU-2026:3596-1, Amazon Linux 2023 ALAS2023-2026-1990) have also been updated (GitHub Advisory, Red Hat Bugzilla).
Red Hat tracked the vulnerability as medium severity in their Bugzilla system, and multiple Linux distributions including Ubuntu, SUSE, Debian, and Amazon Linux issued security advisories and updated packages promptly after the CVE's publication. The vulnerability received routine coverage from security advisory aggregators such as Linux Security and LinuxCompatible, with no notable controversy or significant social media discussion observed. The security community response has been measured, consistent with the limited exploitation potential and availability-only impact of the flaw.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."