CVE-2026-78124: Low severity strongSwan Strongswan vulnerability
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Update strongSwan before relying on openssl plugin PKCS#7 certificate enumeration; if immediate upgrade is not possible, isolate/disable use of the openssl plugin to prevent PKCS#7 certificate enumeration until patched.
Event History
Frequently Asked Questions
What access does an attacker need to attempt exploitation?
The vector is network-based, and no privileges or user interaction are required. Exploitation has high attack complexity.
What is the expected security impact?
The reported impact is limited to confidentiality. No integrity or availability impact is indicated.
Which deployments should be reviewed first?
Review strongSwan installations running versions 5.0.2 through 6.0.7, particularly where the openssl plugin is used for PKCS#7 certificate handling.