An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free… (CVE-2026-13117)
OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 contain an incomplete guard that allows remote authenticated peers to trigger a use-after-free vulnerability during TLS session promotion. This flaw can potentially lead to denial of service or memory leakage.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-13117) affects OpenVPN in versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. An incomplete guard in the code handling TLS session promotion allows remote authenticated peers to trigger a use-after-free condition. This memory management flaw can result in denial of service or memory leakage. The vulnerability is categorized under CWE-416 (Use After Free). No patch or remediation information is currently provided.
Potential Impact
Exploitation of this vulnerability could allow a remote authenticated peer to cause a denial of service or memory leakage in the OpenVPN server or client. This could disrupt VPN connectivity or potentially degrade system stability due to memory corruption.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to trusted authenticated peers and monitor for unusual behavior related to TLS session promotion. Avoid exposing vulnerable OpenVPN instances to untrusted networks.
An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free… (CVE-2026-13117)
Description
OpenVPN versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 contain an incomplete guard that allows remote authenticated peers to trigger a use-after-free vulnerability during TLS session promotion. This flaw can potentially lead to denial of service or memory leakage.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-13117) affects OpenVPN in versions 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4. An incomplete guard in the code handling TLS session promotion allows remote authenticated peers to trigger a use-after-free condition. This memory management flaw can result in denial of service or memory leakage. The vulnerability is categorized under CWE-416 (Use After Free). No patch or remediation information is currently provided.
Potential Impact
Exploitation of this vulnerability could allow a remote authenticated peer to cause a denial of service or memory leakage in the OpenVPN server or client. This could disrupt VPN connectivity or potentially degrade system stability due to memory corruption.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to trusted authenticated peers and monitor for unusual behavior related to TLS session promotion. Avoid exposing vulnerable OpenVPN instances to untrusted networks.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6qjm-gj5v-hp7g
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-13117"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a6bde1a9c2644c7f8dcae7e
Added to database: 07/30/2026, 23:28:26 UTC
Last enriched: 07/31/2026, 00:15:02 UTC
Last updated: 07/31/2026, 00:15:02 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.