What is CVE-2026-12932?
A memory leak during tls-crypt-v2 client key extraction in OpenVPN versions 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets. Affected users should immediately upgrade to a patched version.
Azərbaycanca: OpenVPN-in 2.5.0 - 2.6.20 və 2.7_alpha1 - 2.7.4 versiyalarında tls-crypt-v2 müştəri açarının çıxarılması zamanı memory leak aşkarlanıb. Bu, uzaqdan hücum edənlərə xüsusi hazırlanmış paket seli ilə denial of service (yaddaşın tükənməsi) yaratmağa imkan verir. Zərərçəkənlər dərhal yamaqlanmış versiyalara yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ1
Which versions of OpenVPN are affected by CVE-2026-12932?
This vulnerability affects OpenVPN versions 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.