VulnSea

strongswan has 11 CVEs on record. Disclosure cadence is accelerating: 11 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 11. The median CVSS is 5.9 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-401 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
Last 90 days
11 prev 0

Products

  • strongswan 11
11
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

strongswan vulnerabilities

CVEs affecting strongswan, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-78130High· 7.5
1w ago

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-78124Low· 3.7
1w ago

strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.

strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.

Sunlitstrongswan · strongswanEPSS 0.19%via NVD
CVE-2026-78131Low· 3.7
1w ago

strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.

Sunlitstrongswan · strongswanEPSS 0.23%via NVD
CVE-2026-78134High· 7.1
1w ago

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.

Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-78133High· 7.5
1w ago

libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.

Twilightstrongswan · strongswanEPSS 0.43%via NVD
CVE-2026-78127Low· 3.7
1w ago

libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.

Sunlitstrongswan · strongswanEPSS 0.35%via NVD
CVE-2026-78129Medium· 5.9
1w ago

strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.

Sunlitstrongswan · strongswanEPSS 0.41%via NVD
CVE-2026-78135Medium· 5.6
1w ago

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

Sunlitstrongswan · strongswanEPSS 0.36%via NVD
CVE-2026-78132High· 7.5
1w ago

strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.

Twilightstrongswan · strongswanEPSS 0.32%via NVD
CVE-2026-78126Medium· 5.9
1w ago

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.

Sunlitstrongswan · strongswanEPSS 0.41%via NVD
CVE-2026-78123Medium· 5.9
1w ago

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.

Sunlitstrongswan · strongswanEPSS 0.41%via NVD
strongswan vulnerabilities (CVEs) · VulnSea