
Do you really have to ask so primitively like this is some random toy app and not a security critical VPN tool that sat completely dead for over four years with zero updates? Fine. There was CVE-2023-35838 in the old 0.5.3 version. The firewall rules were set up like shit and let an attacker on the local network force your machine to block local traffic even when the VPN was fully running. Not exactly a great look for a VPN right? There was also CVE-2021-46873 where someone could fuck with the system time and permanently kill your static private keys. But honestly the CVEs are the smallest part of it. The real issue is four straight years of total neglect. No compatibility fixes for new Windows versions (a ton of people were screwed on 11 24H2), no Go runtime security bumps, no performance or MTU improvements nothing at all even though all that work was sitting ready in the repo the whole time.
Post summary
The text briefly mentions two CVEs with rough technical details but focuses more on the software’s prolonged lack of updates and broader security negligence.
