CVE-2026-81738

Summary

OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write via crafted DOMAIN-SEARCH entries

Affected Software

VendorProductVersion RangeStatus
OpenVPNOpenVPN2.5.0 <= 2.7.6affected

Weaknesses

  • CWE-121: CWE-121 Stack-based buffer overflow
  • CWE-193: CWE-193 Off-by-one error
  • CWE-787: CWE-787 Out-of-bounds write

References