CVE-2026-78123: Medium severity strongSwan Strongswan vulnerability
Published Sep 11, 2026
·Updated
strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
Affected Software
1 affected component
strongSwan Strongswan>=5.0.2<=6.0.7
Event History
Sep 11, 2026
CVE Published
via MITRE·01:26 AM
Data Sourced
via MITRE·01:26 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Deployments using strongSwan versions 5.0.2 through 6.0.7 are affected when the openssl plugin performs PKCS#7 parsing.
2
What does an attacker need to exploit this issue?
The published vector indicates network reachability, no privileges, and no user interaction are required. Exploitation has high attack complexity.
3
What is the likely impact?
The vulnerability affects availability only; confidentiality and integrity are not impacted according to the provided severity vector. Successful exploitation can cause a denial of service.
4
What version should be used to remediate the issue?
The affected range ends at 6.0.7, and the provided release reference is for strongSwan 6.1.0.