No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Memory Corruption and Sensitive Information Disclosure via Crafted NRPT Inputs in Windows Interactive Service | OpenVPN: OpenVPN: Memory corruption and information disclosure vulnerability |
| Weaknesses | CWE-120 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Mon, 07 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Memory Corruption and Sensitive Information Disclosure via Crafted NRPT Inputs in Windows Interactive Service | |
| First Time appeared |
Openvpn
Openvpn openvpn |
|
| Vendors & Products |
Openvpn
Openvpn openvpn |
Mon, 07 Sep 2026 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect buffer size calculation in the Windows Interactive Service in OpenVPN 2.7_alpha1 through 2.7.6 allows local authenticated users to cause memory corruption or disclose sensitive information via crafted NRPT inputs. | |
| Weaknesses | CWE-131 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: OpenVPN
Published:
Updated: 2026-09-08T14:54:43.480Z
Reserved: 2026-08-26T14:41:20.459Z
Link: CVE-2026-78221
Updated: 2026-09-08T14:54:38.181Z
Status : Awaiting Analysis
Published: 2026-09-07T08:17:12.813
Modified: 2026-09-08T19:07:52.113
Link: CVE-2026-78221
OpenCVE Enrichment
Updated: 2026-09-08T02:00:20Z