PureVPN Linux Clients Contain IPv6 Leak Vulnerabilities
By
todsacerdoti
8mo ago· 2 min readenNews
65/100
Toasty
Bagelometer↗
Lightly toasted, lightly seasoned, mostly correct.
Score65TypenewsSentimentnegative
Summary
A security researcher discloses two IPv6 leak vulnerabilities in PureVPN's Linux clients (GUI v2.10.0 and CLI v2.0.1) after the company failed to respond to security reports submitted through their VDP program. The vulnerabilities cause IPv6 traffic to leak outside the VPN tunnel when toggling Wi-Fi or resuming from suspend on Ubuntu 24.04.3 LTS systems.
Key quotes
· 3 pulledIn late August 2025, I submitted two security reports to PureVPN under their VDP
Three weeks later, I've received no response, so I decided to publish the findings to inform other users
After toggling Wi-Fi or resuming from suspend, the PureVPN client fails to restore IPv6 protections
In late August 2025, I submitted two security reports to PureVPN under their VDP. Three weeks later, I’ve received no response, so I decided to publish the findings to inform other users.
The issues affect both their GUI (v2.10.0) and CLI (v2.0.1) clients
