OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows...
Low severity
Unreviewed
Published
Aug 15, 2026
to the GitHub Advisory Database
•
Updated Aug 15, 2026
Description
Published by the National Vulnerability Database
Aug 14, 2026
Published to the GitHub Advisory Database
Aug 15, 2026
Last updated
Aug 15, 2026
OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field
References