CVE-2026-78132: High severity strongSwan Strongswan vulnerability
Published Sep 11, 2026
·Updated
strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.
Affected Software
1 affected component
strongSwan Strongswan>=5.1.3<=6.0.7
Event History
Sep 11, 2026
CVE Published
via MITRE·01:49 AM
Data Sourced
via MITRE·01:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to trigger the issue?
The CVSS vector indicates network access is sufficient, with low attack complexity. It does not require privileges or user interaction.
2
What is the expected security impact?
The issue can cause an infinite loop, resulting in a denial of service. The supplied CVSS vector indicates no confidentiality or integrity impact, but a high availability impact.