{"id":"CVE-2025-13086","title":"Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denia…","summary":"Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denia…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-940"],"vendor":"openvpn","product":"openvpn","affected":["openvpn >= 2.6.0, < 2.6.16","openvpn = 2.7"],"patched":["openvpn 2.6.16"],"published":"2025-12-03","updated":"2026-09-25","sourceUpdated":"2026-09-25T23:10:00.463","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-13086","references":[{"url":"https://community.openvpn.net/Security%20Announcements/CVE-2025-13086","label":"security@openvpn.net"},{"url":"https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00151.html","label":"security@openvpn.net"},{"url":"https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00152.html","label":"security@openvpn.net"}],"tags":["nvd"],"epss":0.00641,"epssPercentile":0.48556,"ingestedAt":"2026-09-25T23:21:16.871Z","slug":"CVE-2025-13086","body":"## Overview\n\nImproper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client\n\n## Affected\n\n- `openvpn >= 2.6.0, < 2.6.16`\n- `openvpn = 2.7`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `openvpn 2.6.16`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}