CVE-2026-35058 Details
Description
Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.
A denial-of-service vulnerability has been identified in OpenVPN versions 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1. The issue arises from improper validation of packet length during the tls-crypt-v2 key extraction process, allowing authenticated attackers to trigger a fatal assertion and cause a crash by sending a specially crafted packet.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2026-2381 | CVE | ExploitMitigationThird Party Advisory |
| https://community.openvpn.net/ReleaseHistory#openvpn-2620-released-22-april-2026 | [email protected] | Release Notes |
| https://community.openvpn.net/ReleaseHistory#openvpn-272-released-22-april-2026 | [email protected] | Release Notes |
| https://community.openvpn.net/Security%20Announcements/CVE-2026-35058 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-617 | Reachable Assertion | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| openvpn openvpn | >= 2.6.0, < 2.6.20 >= 2.7, < 2.7.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 11, 2026 | Initial Analysis | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 8, 2026 | CVE Modified | CVE |
| Jun 8, 2026 | New CVE Received | [email protected] |