What is CVE-2026-11771?
OpenVPN versions 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 contain an off-by-one buffer write vulnerability in NTLM proxy authentication. A malicious proxy server can exploit this with a crafted NTLM response to potentially cause a crash.
Azərbaycanca: OpenVPN-in 2.1.0-2.6.20 və 2.7_alpha1-2.7.4 versiyalarında NTLM proxy autentifikasiyasında off-by-one buffer yazma zəifliyi mövcuddur. Bu, zərərli proxy serverindən gələn xüsusi hazırlanmış NTLM cavabı vasitəsilə xidmətin çökməsinə səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which versions of OpenVPN are affected by CVE-2026-11771?
This vulnerability affects OpenVPN versions 2.1.0 through 2.6.20, as well as versions 2.7_alpha1 through 2.7.4.
How can an attacker exploit CVE-2026-11771?
An attacker can exploit this by using a malicious proxy server to send a crafted NTLM response, potentially causing a crash.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.