Memory Management Flaw in IKE Message Parser of strongSwan
CVE-2026-78127

3.7LOW

Key Information:

Vendor

Strongswan

Vendor
CVE Published:
11 September 2026

What is CVE-2026-78127?

A memory management issue exists in the IKE message parser component of strongSwan, specifically impacting versions 4.1.2 through 6.0.7. This vulnerability leads to a failure in releasing memory after its effective lifetime, potentially allowing for atypical behavior or resource exhaustion in applications depending on the IKE message parsing functionality. Proper remediation involves updating to versions that address this oversight.

Affected Version(s)

strongSwan 4.1.2 < 6.1.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.