CVE-2026-78129: Medium severity strongSwan Strongswan vulnerability
Published Sep 11, 2026
·Updated
strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
Affected Software
1 affected component
strongSwan Strongswan>=4.6.2<=6.0.7
Event History
Sep 11, 2026
CVE Published
via MITRE·01:40 AM
Data Sourced
via MITRE·01:40 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
No privileges or user interaction are required according to the CVSS vector. The attack vector is network-based.
2
What is the expected security impact if exploitation succeeds?
The reported impact is limited to availability, rated High. No confidentiality or integrity impact is reported.
3
How difficult is exploitation expected to be?
The attack complexity is rated High, indicating exploitation requires conditions beyond simply reaching a vulnerable network service.