
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35331 is a reserved CVE identifier associated with a vulnerability in strongSwan, an open-source IPsec-based VPN solution widely deployed on Linux and other Unix-like systems. The CVE was first detected and discussed around April 22, 2026, with vendor advisories from Debian, Ubuntu, SUSE, and FreeBSD referencing it in the context of strongSwan security updates (Debian Advisory, SUSE Advisory). Feedly AI estimates the severity as HIGH, though an official CVSS score has not yet been published as the vulnerability details remain pending in the CVE database (Feedly). Multiple scanner detections have been published by Tenable (Nessus plugins 309664, 309912, 313701, 313690, 315970) and Qualys (detection ID 6275335), indicating active scanner coverage.
Full technical details for CVE-2026-35331 have not yet been publicly disclosed, as the CVE remains in a reserved state. Based on contextual signals from community discussions — including a blog post referencing "strongSwan VPN servers infinite loop" — the vulnerability may involve a denial-of-service condition triggered by malformed or crafted IKE (Internet Key Exchange) packets, potentially causing an infinite loop in the strongSwan daemon (Portal Linux). The affected component and precise attack vector have not been officially confirmed. CWE classification is not yet assigned.
If the infinite loop characterization is accurate, successful exploitation could cause the strongSwan IKE daemon (charon) to become unresponsive, resulting in a denial of service for all VPN connections handled by the affected server. This would impact availability of VPN infrastructure, potentially disrupting remote access, site-to-site tunnels, and network segmentation controls that depend on strongSwan. The scope of impact would depend on deployment scale, but internet-facing VPN gateways would be at highest risk (Portal Linux, Debian Advisory).
No public proof-of-concept exploit code has been identified at this time, and there is no confirmed evidence of in-the-wild exploitation. The CVE has not been listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS score data is not yet available given the reserved status of the CVE. However, the rapid publication of detection plugins by Tenable and Qualys, along with multi-distribution vendor advisories, suggests the vulnerability is considered significant enough to warrant prompt patching (Tenable Nessus).
Multiple Linux distributions have released updated strongSwan packages addressing CVE-2026-35331. Administrators should apply the relevant vendor updates as soon as possible:
As a temporary workaround, consider restricting IKE traffic (UDP 500/4500) to trusted IP ranges via firewall rules to reduce exposure of internet-facing strongSwan instances until patching is complete.
The vulnerability has received coverage across Linux security news aggregators and German-language Linux security outlets (Pro-Linux.de), with multiple updates published as additional distribution advisories were released (Pro-Linux). Community discussion has been moderate, consistent with a VPN daemon vulnerability affecting a widely-deployed open-source package. No notable individual researcher commentary or major media coverage has been identified beyond standard advisory tracking.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."