Description
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
Published: 2026-09-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Upgrade
AI Analysis

Impact

The vulnerability is a NULL pointer dereference in the X.509 attribute certificate parser of strongSwan. When an attacker supplies a crafted attribute certificate, to crash or become unresponsive. This failure can lead to a denial of service.

Affected Systems

strongSwan, versions 4.2.0 through 6.0.7, which can be obtained from the official release page.

Risk and Exploitability

The CVSS score of 7.5 indicates a moderate to high severity. EPSS data is not available and it is not listed in the CISA KEV catalog, suggesting that no confirmed exploits are widespread. The likely attack vector is an attacker sending a malicious certificate over the network, which, if the server is configured to accept attribute certificates, could trigger the crash.

Generated by OpenCVE AI on September 11, 2026 at 04:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to strongSwan 6.1.0 or later
  • If a quick upgrade is not possible, disable the X.509 attribute certificate functionality or restrict certificate validation to trusted certificates only
  • Implement monitoring to detect sudden crashes or hangs and automatically restart the service

Generated by OpenCVE AI on September 11, 2026 at 04:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6487-1 strongswan security update
Ubuntu USN Ubuntu USN USN-8789-1 strongSwan vulnerabilities
History

Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in strongSwan X.509 Attribute Certificate Parser

Fri, 11 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
First Time appeared Strongswan
Strongswan strongswan
Weaknesses CWE-476
CPEs cpe:2.3:a:strongswan:strongswan:*:*:*:*:*:*:*:*
Vendors & Products Strongswan
Strongswan strongswan
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Strongswan Strongswan
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T15:30:16.065Z

Reserved: 2026-08-22T23:32:38.352Z

Link: CVE-2026-78130

cve-icon Vulnrichment

Updated: 2026-09-15T15:30:11.200Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-11T02:18:34.353

Modified: 2026-09-15T16:17:24.987

Link: CVE-2026-78130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T06:30:05Z

Weaknesses