Description
Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag appears at the end of the encrypted packet
Scores
CVSS v4
5.6
EPSS
0.0002
EPSS Percentile
5.9%
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:P
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-131
Status
published
Products (1)
OpenVPN/ovpn-dco-win
2.8.0
Published
Feb 19, 2026
Tracked Since
Feb 20, 2026