CVE-2026-13379
Awaiting Analysis Awaiting Analysis - Queue

Windows Interactive Service DNS Pollution in OpenVPN

Vulnerability report for CVE-2026-13379, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-07-30

Assigner: OpenVPN Inc.

Description

The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-07-30
Generated
2026-07-31
AI Q&A
2026-07-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
openvpn openvpn From 2.7_alpha1 (inc) to 2.7.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.
CWE-142 The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as value delimiters when they are sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash by sending a crafted search domain during the disconnection process.

Impact Analysis

It could lead to DNS issues like incorrect domain resolution or service disruptions, potentially affecting network connectivity or application functionality.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unauthorized DNS state changes or service disruptions. Persistent DNS pollution may lead to data exfiltration or misrouting, which could violate data integrity and confidentiality requirements under these regulations.

Mitigation Strategies

Update OpenVPN to a version that patches this vulnerability. Disable the Windows interactive service if not required. Monitor DNS logs for unusual search domain activity during disconnection.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13379. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart