
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-13117 is a use-after-free vulnerability in OpenVPN affecting versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. An incomplete guard during TLS session promotion allows remote authenticated peers to trigger the flaw, potentially resulting in denial of service or memory leakage. The vulnerability was published on July 30, 2026, with patches released in OpenVPN 2.6.21 and 2.7.5. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 6.0 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an incomplete guard in OpenVPN's TLS session promotion logic, classified as CWE-416 (Use After Free) and CWE-825 (Expired Pointer Dereference). During TLS session promotion — the process by which a connection transitions between TLS states — a memory region can be freed while a reference to it is still retained, allowing subsequent dereference of the freed memory. Exploitation requires network access and low-level authentication (an authenticated peer), but no user interaction. A technical write-up discussing the TLS crypt v2 heap use-after-free angle has been published by undercode testing (Undercode Testing, GitHub Advisory).
Successful exploitation by a remote authenticated peer can cause the OpenVPN service to crash (denial of service) or leak sensitive data from process memory, which may include cryptographic material or session data. The confidentiality impact is rated High under CVSS v3.1, and availability impact is also High, while integrity is unaffected. The vulnerability is scoped to the vulnerable system itself, with no direct impact on subsequent systems, though memory leakage could facilitate further attacks (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of reporting (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS score is approximately 0.37–0.40%, placing it in the 33rd percentile for exploitation likelihood within 30 days. Exploitation is not automatable and requires the attacker to already hold valid VPN credentials, significantly limiting the attack surface (GitHub Advisory).
/var/log/syslog, /var/log/openvpn.log); error messages referencing TLS session promotion or memory access violations.core, core.<pid>) in the OpenVPN installation or working directory following service crashes.Upgrade OpenVPN to version 2.6.21 or later for the 2.6.x branch, or version 2.7.5 or later for the 2.7.x branch, as these releases contain the fix for the incomplete TLS guard (GitHub Advisory). Distribution-specific packages are available for Ubuntu (USN-8540-1), SUSE (SUSE-SU-2026:3596-1), Amazon Linux 2023 (ALAS2023-2026-2038), and others. As a temporary measure, restrict VPN access to only trusted, known-good clients and monitor for unexpected service crashes.
The OpenVPN project published an official security announcement and release history entries for the patched versions (OpenVPN Community). Undercode Testing published a technical blog post and video framing the issue as a TLS crypt v2 heap use-after-free with potential RCE implications, which generated discussion on Bluesky (Undercode Testing). Multiple Linux distributions including Ubuntu, SUSE, Mageia, Alpine, and FreeBSD responded promptly with updated packages, reflecting the broad deployment of OpenVPN across infrastructure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."