Technology · strongSwan
strongSwan vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in strongSwan: 0 in the last 7 days and 12 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-78135, was published on 11 September 2026.
- Last 7 days
- 0
- Last 90 days
- 12
- Critical, all time
- 0
- Exploited in the wild
- 0
About strongSwan
strongSwan is an open-source IPsec-based VPN solution for Linux and other operating systems.
Latest strongSwan vulnerabilities
- CVE-2026-78135: strongSwan libcharon authentication bypass in IKEv2 CREATE_CHILD_SA handlingmediumCVSS 5.6EPSS 0.4%
- CVE-2026-78134: strongSwan incorrect identity binding in EAP-PEAP and EAP-TTLShighCVSS 7.1EPSS 0.3%
- CVE-2026-78133: strongSwan libcharon use-after-free in IKEv2 rekeying collision handlinghighCVSS 7.5EPSS 0.4%
- CVE-2026-78132: strongSwan x509 plugin infinite loop in ietfAttrSyntax parsinghighCVSS 7.5EPSS 0.3%
- CVE-2026-78131: strongSwan x509 plugin memory leak in attribute certificate parsinglowCVSS 3.7EPSS 0.2%
- CVE-2026-78130: strongSwan x509 plugin NULL pointer dereference in attribute certificate validationhighCVSS 7.5EPSS 0.3%
- CVE-2026-78129: strongSwan infinite loop in PKCS#5 decryptionmediumCVSS 5.9EPSS 0.4%
- CVE-2026-78127: strongSwan libcharon memory leak in IKE message logginglowCVSS 3.7EPSS 0.4%
- CVE-2026-78126: strongSwan NULL pointer dereference in eap-aka pluginmediumCVSS 5.9EPSS 0.4%
- CVE-2026-78124: strongSwan openssl plugin memory leak in PKCS#7 certificate enumerationlowCVSS 3.7EPSS 0.2%
- CVE-2026-78123: strongSwan openssl plugin expired pointer dereference in PKCS#7 parsingmediumCVSS 5.9EPSS 0.4%
- CVE-2026-47895: strongSwan EAP-Identity parsing double-free in libstrongswanhighCVSS 7.5EPSS 0.4%
- CVE-2026-25075: strongSwan integer underflow in EAP-TTLS AVP parserhighCVSS 7.5EPSS 1.0%
Most severe strongSwan vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-25075: strongSwan integer underflow in EAP-TTLS AVP parserhighCVSS 7.5EPSS 1.0%
- CVE-2026-78133: strongSwan libcharon use-after-free in IKEv2 rekeying collision handlinghighCVSS 7.5EPSS 0.4%
- CVE-2026-47895: strongSwan EAP-Identity parsing double-free in libstrongswanhighCVSS 7.5EPSS 0.4%
- CVE-2026-78132: strongSwan x509 plugin infinite loop in ietfAttrSyntax parsinghighCVSS 7.5EPSS 0.3%
- CVE-2026-78130: strongSwan x509 plugin NULL pointer dereference in attribute certificate validationhighCVSS 7.5EPSS 0.3%
- CVE-2026-78134: strongSwan incorrect identity binding in EAP-PEAP and EAP-TTLShighCVSS 7.1EPSS 0.3%
- CVE-2026-78129: strongSwan infinite loop in PKCS#5 decryptionmediumCVSS 5.9EPSS 0.4%
- CVE-2026-78126: strongSwan NULL pointer dereference in eap-aka pluginmediumCVSS 5.9EPSS 0.4%
- CVE-2026-78123: strongSwan openssl plugin expired pointer dereference in PKCS#7 parsingmediumCVSS 5.9EPSS 0.4%
- CVE-2026-78135: strongSwan libcharon authentication bypass in IKEv2 CREATE_CHILD_SA handlingmediumCVSS 5.6EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 11 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/strongswan.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "strongSwan vulnerabilities", https://junglewise.ai/threats/technologies/strongswan, 26 September 2026.