CVE-2026-78135
- EPSS 0.34%
- Veröffentlicht 11.09.2026 02:07:28
- Zuletzt bearbeitet 16.09.2026 19:37:30
libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.
CVE-2026-78134
- EPSS 0.32%
- Veröffentlicht 11.09.2026 02:00:46
- Zuletzt bearbeitet 14.09.2026 20:06:44
strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
CVE-2026-78133
- EPSS 0.42%
- Veröffentlicht 11.09.2026 01:52:30
- Zuletzt bearbeitet 14.09.2026 20:07:44
libcharon in strongSwan 6.0.0 through 6.0.7 has a use-after-free in IKEv2 rekeying collision handling.
CVE-2026-78132
- EPSS 0.31%
- Veröffentlicht 11.09.2026 01:49:15
- Zuletzt bearbeitet 14.09.2026 20:08:12
strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x509 plugin's attribute certificate parser for ietfAttrSyntax.
CVE-2026-78131
- EPSS 0.23%
- Veröffentlicht 11.09.2026 01:45:58
- Zuletzt bearbeitet 14.09.2026 20:08:24
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
CVE-2026-78130
- EPSS 0.31%
- Veröffentlicht 11.09.2026 01:43:43
- Zuletzt bearbeitet 15.09.2026 16:17:24
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
CVE-2026-78129
- EPSS 0.41%
- Veröffentlicht 11.09.2026 01:40:01
- Zuletzt bearbeitet 14.09.2026 20:08:56
strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
CVE-2026-78127
- EPSS 0.35%
- Veröffentlicht 11.09.2026 01:37:05
- Zuletzt bearbeitet 14.09.2026 20:09:10
libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
CVE-2026-78126
- EPSS 0.41%
- Veröffentlicht 11.09.2026 01:33:50
- Zuletzt bearbeitet 14.09.2026 20:09:26
strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
CVE-2026-78124
- EPSS 0.19%
- Veröffentlicht 11.09.2026 01:30:47
- Zuletzt bearbeitet 14.09.2026 20:09:47
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.