Memory Management Flaw in strongSwan's x509 Plugin
CVE-2026-78131

3.7LOW

Key Information:

Vendor

Strongswan

Vendor
CVE Published:
11 September 2026

What is CVE-2026-78131?

The strongSwan software, specifically versions 4.2.0 through 6.0.7, contains a memory management vulnerability associated with the x509 plugin's attribute certificate parser. This flaw allows for memory to be retained after it has served its purpose, leading to potential leaks that could impact system performance and stability. Users are advised to evaluate their current versions and apply the necessary updates to mitigate this issue effectively.

Affected Version(s)

strongSwan 4.2.0 < 6.1.0

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.