CVE-2026-78131: Low severity strongSwan Strongswan vulnerability
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Mitigate the strongSwan x509 plugin missing-release-of-memory issue after certificate attribute effective lifetime by limiting exposure/requests that trigger the x509 attribute certificate parser until an upstream fix is applied (use compensating controls such as rate limiting or restricting access to the affected service).
Event History
Frequently Asked Questions
Which deployments are affected?
strongSwan versions 4.2.0 through 6.0.7 are affected. The issue is in the x509 plugin's attribute certificate parser.
What access does an attacker need to exploit this issue?
The supplied vector indicates network reachability, no privileges, and no user interaction are required. Exploitation has high attack complexity and is limited to an availability impact.
What is the remediation version?
The provided release reference identifies strongSwan 6.1.0. Organizations running affected versions should review that release as the available update path.