Junglewise Threat Intelligence

CVE-2026-13698: OpenVPN memory leak in tls-crypt-v2 handling

CVE-2026-13698 · Severity: info · CVSS 6 · Published 2026-07-06

Technologies: OpenVPN Inc. Openvpn.

Executive brief

A memory leak vulnerability has been identified in OpenVPN, a widely used software for creating secure point-to-point or site-to-site connections. An attacker with a valid client key can repeatedly trigger this leak to exhaust the server's available memory. This can lead to a denial-of-service condition, causing the VPN service to crash or become unresponsive for all users.

Technical details

A memory leak exists in OpenVPN (versions 2.5.0-2.5.11, 2.6.0-2.6.20, and 2.7_alpha1-2.7.4) due to the missing release of memory after its effective lifetime (CWE-401). The vulnerability is triggered during the handling of tls-crypt-v2 client keys. A remote attacker possessing a valid tls-crypt-v2 key can exploit this by initiating multiple connections or requests that allocate memory without subsequent deallocation. Over time, this results in resource exhaustion (CWE-770), leading to a denial-of-service (DoS) against the OpenVPN server. While the attack requires a valid key, it can be executed over the network.

Affected products

  • OpenVPN Inc. OpenVPN 2.5.0 through 2.5.11, 2.6.0 through 2.6.20, 2.7_alpha1 through 2.7.4

Timeline

  • 2026-07-06: disclosed: Initial disclosure of CVE-2026-13698
  • 2026-07-06: advisory: NVD record published

References