{
  "threat_severity" : "Moderate",
  "public_date" : "2026-07-30T16:32:42Z",
  "bugzilla" : {
    "description" : "OpenVPN: OpenVPN: Denial of service or memory leakage via incomplete TLS guard",
    "id" : "2509530",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2509530"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.9",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H",
    "status" : "draft"
  },
  "cwe" : "CWE-825",
  "details" : [ "An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage", "A flaw was found in OpenVPN. An incomplete guard allows remote authenticated peers to trigger a use-after-free vulnerability during TLS (Transport Layer Security) session promotion. This can lead to a denial of service, making the service unavailable, or memory leakage, which could potentially expose sensitive information." ],
  "statement" : "Moderate: This flaw in OpenVPN allows a remote authenticated peer to trigger a use-after-free during TLS session promotion, leading to a denial of service or memory leakage. The high attack complexity and requirement for prior authentication limit the immediate risk, but successful exploitation could disrupt VPN services or expose sensitive information.",
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-13117\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-13117\nhttps://community.openvpn.net/ReleaseHistory#openvpn-2621-released-1-july-2026\nhttps://community.openvpn.net/ReleaseHistory#openvpn-275-released-1-july-2026\nhttps://community.openvpn.net/Security%20Announcements/CVE-2026-13117" ],
  "name" : "CVE-2026-13117",
  "csaw" : false
}