CVE-2026-35331
strongSwan vulnerability analysis and mitigation

Overview

CVE-2026-35331 is a reserved CVE identifier associated with a vulnerability in strongSwan, an open-source IPsec-based VPN solution widely deployed on Linux and other Unix-like systems. The CVE was first detected and discussed around April 22, 2026, with vendor advisories from Debian, Ubuntu, SUSE, and FreeBSD referencing it in the context of strongSwan security updates (Debian Advisory, SUSE Advisory). Feedly AI estimates the severity as HIGH, though an official CVSS score has not yet been published as the vulnerability details remain pending in the CVE database (Feedly). Multiple scanner detections have been published by Tenable (Nessus plugins 309664, 309912, 313701, 313690, 315970) and Qualys (detection ID 6275335), indicating active scanner coverage.

Technical details

Full technical details for CVE-2026-35331 have not yet been publicly disclosed, as the CVE remains in a reserved state. Based on contextual signals from community discussions — including a blog post referencing "strongSwan VPN servers infinite loop" — the vulnerability may involve a denial-of-service condition triggered by malformed or crafted IKE (Internet Key Exchange) packets, potentially causing an infinite loop in the strongSwan daemon (Portal Linux). The affected component and precise attack vector have not been officially confirmed. CWE classification is not yet assigned.

Impact

If the infinite loop characterization is accurate, successful exploitation could cause the strongSwan IKE daemon (charon) to become unresponsive, resulting in a denial of service for all VPN connections handled by the affected server. This would impact availability of VPN infrastructure, potentially disrupting remote access, site-to-site tunnels, and network segmentation controls that depend on strongSwan. The scope of impact would depend on deployment scale, but internet-facing VPN gateways would be at highest risk (Portal Linux, Debian Advisory).

Exploitability

No public proof-of-concept exploit code has been identified at this time, and there is no confirmed evidence of in-the-wild exploitation. The CVE has not been listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS score data is not yet available given the reserved status of the CVE. However, the rapid publication of detection plugins by Tenable and Qualys, along with multi-distribution vendor advisories, suggests the vulnerability is considered significant enough to warrant prompt patching (Tenable Nessus).

Mitigation and workarounds

Multiple Linux distributions have released updated strongSwan packages addressing CVE-2026-35331. Administrators should apply the relevant vendor updates as soon as possible:

As a temporary workaround, consider restricting IKE traffic (UDP 500/4500) to trusted IP ranges via firewall rules to reduce exposure of internet-facing strongSwan instances until patching is complete.

Community reactions

The vulnerability has received coverage across Linux security news aggregators and German-language Linux security outlets (Pro-Linux.de), with multiple updates published as additional distribution advisories were released (Pro-Linux). Community discussion has been moderate, consistent with a VPN daemon vulnerability affecting a widely-deployed open-source package. No notable individual researcher commentary or major media coverage has been identified beyond standard advisory tracking.

Additional resources


SourceThis report was generated using AI

Related strongSwan vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47895HIGH7.5
  • strongSwan logostrongSwan
  • perl-vici
NoYesAug 22, 2026
CVE-2026-35334NONEN/A
  • strongSwan logostrongSwan
  • strongswan-sqlite
NoYesApr 22, 2026
CVE-2026-35333NONEN/A
  • strongSwan logostrongSwan
  • strongswan-doc
NoYesApr 22, 2026
CVE-2026-35332NONEN/A
  • strongSwan logostrongSwan
  • strongswan
NoYesApr 22, 2026
CVE-2026-35331NONEN/A
  • strongSwan logostrongSwan
  • strongswan-fips
NoYesApr 22, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management