Description
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
Published: 2026-09-11
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: Memory Leak leading to potential Denial of Service
Action: Update
AI Analysis

Impact

strongSwan versions 5.0.2 through 6.0.7 contain a flaw in the OpenSSL plugin that permits PKCS#7 certificate enumeration. The routine fails to release memory after the objects’ effective lifetime, creating a memory leak (CWE‑401). Although each individual leak may be small, repeated use over time can exhaust system memory and cause a denial‑of‑service condition for the strongSwan process.

Affected Systems

The vulnerability affects the strongSwan vendor’s open‑source VPN software, specifically all releases between 5.0.2 and 6.0.7 inclusive. Clients running these versions on any platform that uses the OpenSSL plugin are at risk.

Risk and Exploitability

The CVSS score of 3.7 indicates low severity, and no EPSS value is available, so the likelihood of exploitation is unknown. This vulnerability is not listed in CISA’s KE vector could be remote if an adversary can force the strongSwan server to enumerate certificates, but the precise vector is not explicitly stated in the advisory; it is inferred that remote access to the OpenSSL plugin is required.

Generated by OpenCVE AI on September 11, 2026 at 03:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade strongSwan to version 6.1.0 or newer to fix the memory release bug.
  • Disable the vulnerable OpenSSL plugin or block certificate enumeration when unnecessary to reduce exposure.
  • Monitor system memory usage and logs for leaks, and configure an alert if memory consumption grows beyond normal thresholds.

Generated by OpenCVE AI on September 11, 2026 at 03:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6487-1 strongswan security update
Ubuntu USN Ubuntu USN USN-8789-1 strongSwan vulnerabilities
History

Sat, 12 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title StrongSwan PKCS#7 Certificate Enumeration Memory Leak

Fri, 11 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
First Time appeared Strongswan
Strongswan strongswan
Weaknesses CWE-401
CPEs cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
Vendors & Products Strongswan
Strongswan strongswan
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-11T20:05:22.532Z

Reserved: 2026-08-22T23:25:55.893Z

Link: CVE-2026-78124

cve-icon Vulnrichment

Updated: 2026-09-11T20:05:18.728Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T02:18:33.770

Modified: 2026-09-14T20:09:47.260

Link: CVE-2026-78124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T18:30:13Z

Weaknesses
  • CWE-401

    Missing Release of Memory after Effective Lifetime