Known Vulnerabilities for products from Strongswan
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Strongswan".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-94417 json | Not Provided | 2026-09-27 | 2026-09-29 | |
| CVE-2026-78135 json | libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_... | Not Provided | 2026-09-11 | 2026-09-16 |
| CVE-2026-78134 json | strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missi... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-78133 json | Not Provided | 2026-09-11 | 2026-09-11 | |
| CVE-2026-78132 json | strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax. | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-78131 json | strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute ce... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-78130 json | Not Provided | 2026-09-11 | 2026-09-15 | |
| CVE-2026-78129 json | strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption. | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-78127 json | libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message p... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-78126 json | strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin. | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-78124 json | strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of... | Not Provided | 2026-09-11 | 2026-09-14 |
| CVE-2026-78123 json | strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin. | Not Provided | 2026-09-11 | 2026-09-15 |
| CVE-2023-26463 json | strongSwan 5.9.8 and 5.9.9 potentially allows remote code execution because it uses a variable named "public" for two differe... | 9.8 - CRITICAL | 2023-04-15 | 2023-05-17 |
| CVE-2022-40617 json | strongSwan before 5.9.8 allows remote attackers to cause a denial of service in the revocation plugin by sending a crafted en... | 7.5 - HIGH | 2022-10-31 | 2023-11-07 |
| CVE-2021-45079 json | In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating t... | 9.1 - CRITICAL | 2022-01-31 | 2023-11-07 |
| CVE-2021-41991 json | The in-memory certificate cache in strongSwan before 5.9.4 has a remote integer overflow upon receiving many requests with di... | 7.5 - HIGH | 2021-10-18 | 2023-11-07 |
| CVE-2021-41990 json | The gmp plugin in strongSwan before 5.9.4 has a remote integer overflow via a crafted certificate with an RSASSA-PSS signatur... | 7.5 - HIGH | 2021-10-18 | 2023-11-07 |
| CVE-2019-10155 json | The Libreswan Project has found a vulnerability in the processing of IKEv1 informational exchange packets which are encrypted... | 3.1 - LOW | 2019-06-12 | 2023-11-07 |
| CVE-2018-17540 json | The gmp plugin in strongSwan before 5.7.1 has a Buffer Overflow via a crafted certificate. | 7.5 - HIGH | 2018-10-03 | 2023-11-07 |
| CVE-2018-16152 json | In verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA im... | 7.5 - HIGH | 2018-09-26 | 2023-11-07 |
Known software with vulnerabilities from Strongswan
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Strongswan | Davici | 0.1 |
| Application | Strongswan | Strongswan | 2.0.0 |
| Application | Strongswan | Strongswan Vpn Client | 1.4.5 |