Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating clientReferenceshttps://community.openvpn.net/Security%20Announcements/CVE-2025-13086https://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00152.htmlhttps://www.mail-archive.com/openvpn-announce@lists.sourceforge.net/msg00151.html