Junglewise Threat Intelligence

CVE-2026-78130: strongSwan x509 plugin NULL pointer dereference in attribute certificate validation

CVE-2026-78130 · Severity: high · CVSS 7.5 · Published 2026-09-11

Technologies: strongSwan. Vendors: strongSwan.

Executive brief

strongSwan is an open-source IPsec VPN implementation used by organizations to create secure tunnels for network traffic. The x509 plugin, which handles certificate validation, contains a flaw that crashes when processing specially crafted attribute certificates, causing denial of service and interrupting VPN connectivity.

Technical details

A NULL pointer dereference exists in the x509 plugin's attribute certificate validation code. Specifically, the issued_by() and has_issuer() methods unconditionally dereference the issuerName field without checking if it is NULL; per ASN.1 specification, this field is optional in attribute certificates. An attacker with network access can craft an attribute certificate with a missing issuerName field and provide it to strongSwan for validation, triggering a crash in the acert plugin's certificate validation flow. The vulnerability requires the x509 and acert plugins to be loaded (x509 is loaded by default). Remote code execution is not possible; the impact is limited to denial of service. The fix is available in strongSwan 6.1.0 released 2026-09-07, with patches available for versions 5.1.3 and newer.

Affected products

  • strongSwan strongSwan 4.2.0 through 6.0.7

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Fixed in strongSwan 6.1.0
  • 2026-09-11: advisory: CVE-2026-78130 published on NVD

References

Related threats