Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
https://www.mail-archive.com/[email protected]/msg00152.html
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-199988
https://community.openvpn.net/Security%20Announcements/CVE-2025-12106