OpenVPN 2.7.8 has been released with fixes for three security vulnerabilities, along with several DCO and server reliability improvements.
The first issue, CVE-2026-84790, affects certificate handling. OpenVPN now rejects certificates with subject fields containing embedded NULL bytes. This makes validation stricter on OpenSSL-based builds. mbedTLS already rejected such certificates.
CVE-2026-88964 fixes an unsigned underflow that could occur when clearing the domain_search_list option. CVE-2026-84256 addresses a Windows-specific issue where cmd.exe could expand variables inside quoted arguments.
The release also fixes a tls-crypt-v2 client-side problem where OpenVPN could attempt to add a wrapped client key without having valid key material. No CVE was assigned to that issue.
On the DCO side, OpenVPN 2.7.8 fixes stale iroutes, Linux Netlink race conditions, and errors during peer or key setup. These errors could previously terminate the whole server process instead of only the affected client instance.
Other fixes include more consistent certificate handling between OpenSSL and mbedTLS, better handling of invalid pushed cipher configurations, and a rare point-to-multipoint server queue deadlock.
For more details, see the changelog.
