CVE-2026-2738

MEDIUM

ovpn-dco-win 2.8.0 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Buffer overflow in ovpn‑dco‑win version 2.8.0 allows local attackers to cause a system crash by sending too large packets to the remote peer when the AEAD tag appears at the end of the encrypted packet

Scores

CVSS v4 5.6
EPSS 0.0002
EPSS Percentile 5.9%
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:P

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-131
Status published
Products (1)
OpenVPN/ovpn-dco-win 2.8.0
Published Feb 19, 2026
Tracked Since Feb 20, 2026