What is CVE-2026-13379?
A vulnerability in the OpenVPN Windows interactive service allows remote attackers to cause persistent DNS state pollution or a service crash. Exploited via a crafted search domain during disconnection, it affects versions 2.7_alpha1 through 2.7.4. Updating to a patched version is recommended.
Azərbaycanca: OpenVPN-in Windows interaktiv xidmətində boşluq aşkarlanıb (CVE-2026-13379). Uzaqdan hücumçu, əlaqə kəsmə prosesi zamanı xüsusi hazırlanmış axtarış domeni vasitəsilə davamlı DNS state pollution yarada və ya xidmətin çökməsinə səbəb ola bilər. 2.7_alpha1 və 2.7.4 versiyaları arasındakı OpenVPN istifadəçilərinə təsir edir, yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: OpenVPN
FAQ2
Which platform of OpenVPN is affected by CVE-2026-13379?
This vulnerability affects the OpenVPN Windows interactive service.
What can a remote attacker achieve by exploiting CVE-2026-13379?
A remote attacker can cause persistent DNS state pollution or a service crash.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.