CVE-2026-78130: Null Pointer Dereference
Published Sep 11, 2026
·Updated
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
Affected Software
1 affected component
strongSwan Strongswan>=4.2.0<=6.0.7
Event History
Sep 11, 2026
CVE Published
via MITRE·01:43 AM
Data Sourced
via MITRE·01:43 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
strongSwan versions 4.2.0 through 6.0.7 are affected. The issue is in the x509 plugin's attribute certificate parser.
2
What access does an attacker need to trigger the issue?
The supplied vector indicates network-reachable exploitation with low attack complexity, requiring no privileges or user interaction.
3
What is the likely impact of successful exploitation?
Successful exploitation can cause a denial of service through a NULL pointer dereference. The supplied impact vector indicates no confidentiality or integrity impact.
4
What fixed version is available?
The provided release reference identifies strongSwan 6.1.0 as the release containing the fix.