Expired Pointer Dereference Vulnerability in strongSwan by strongSwan Project
CVE-2026-78123

5.9MEDIUM

Key Information:

Vendor

Strongswan

Vendor
CVE Published:
11 September 2026

What is CVE-2026-78123?

The strongSwan VPN software, versions 5.0.2 through 6.0.7, is affected by an expired pointer dereference vulnerability within the PKCS#7 parsing of its openssl plugin. This flaw allows an attacker to potentially exploit memory handling issues related to expired pointers, leading to unexpected behaviors or crashes within the application. Users are encouraged to update to the latest versions to mitigate any risks associated with this vulnerability.

Affected Version(s)

strongSwan 5.0.2 < 6.1.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.