CVE-2026-78124
strongSwan
Published 11 Sept 2026 · updated 14 Sept 2026 · Analyzed
3.7 Low · CVSS 3.1, mitre.org
Description
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
References
- github.com/strongswan/strongswan/releases/tag/6.1.0 · Patch, Release Notes, Vendor Advisory
- www.strongswan.org/blog/2026/09/07/strongswan-vulnerability-(cve-2026-78124).html · Mitigation, Vendor Advisory