Junglewise Threat Intelligence

CVE-2026-13379: OpenVPN Windows interactive service DNS pollution and denial of service

CVE-2026-13379 · Severity: info · CVSS 5.1 · Published 2026-07-30

Executive brief

OpenVPN is a widely used software for creating secure private network connections. A vulnerability in its Windows service could allow a remote attacker to crash the application or corrupt DNS settings when a user disconnects from the VPN. This could lead to a loss of connectivity or cause the computer to use incorrect network addresses, potentially disrupting business operations or redirecting traffic.

Technical details

A vulnerability exists in the Windows interactive service of OpenVPN (versions 2.7_alpha1 through 2.7.4) involving improper neutralization of value delimiters and an out-of-bounds read (CWE-142, CWE-125). An attacker can exploit this by providing a specially crafted search domain that is processed during the VPN disconnection phase. Successful exploitation can lead to a persistent corrupted DNS state on the host or a denial-of-service (DoS) via a service crash. The attack requires low privileges and some user interaction, but can be initiated over the network. The issue is addressed in OpenVPN version 2.7.5.

Affected products

  • OpenVPN Inc. OpenVPN 2.7_alpha1 through 2.7.4

Timeline

  • 2026-07-01: patched: OpenVPN 2.7.5 released to address the issue
  • 2026-07-30: advisory: CVE-2026-13379 published by OpenVPN Inc. and NVD

References