
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78131 is a memory leak vulnerability in the strongSwan x509 plugin that occurs during the parsing of identities in X.509 attribute certificates, which can lead to a denial of service (DoS) condition. The CVE was reserved and first detected by Feedly on September 7, 2026, with a Debian security advisory (DSA-6487-1) published shortly after. The affected product is strongSwan, a widely used open-source IPsec-based VPN solution. The estimated CVSS severity is Medium (Feedly, Debian Advisory).
The root cause is a memory leak (CWE-401) in strongSwan's x509 plugin, triggered when parsing identity fields within X.509 attribute certificates. An attacker capable of supplying malformed or specially crafted attribute certificates to a vulnerable strongSwan instance can cause repeated memory allocation without corresponding deallocation. This vulnerability requires the target system to process attacker-controlled X.509 attribute certificates, which may occur during IKE negotiation or certificate validation in VPN connections (Feedly, Debian Advisory).
Successful exploitation of this vulnerability results in progressive memory exhaustion on the affected strongSwan host, ultimately causing a denial of service by crashing or severely degrading the VPN daemon. Availability is the primary impact, as the memory leak can render VPN infrastructure inoperable; confidentiality and integrity are not directly affected. In environments where strongSwan serves as a critical network gateway, a DoS condition could disrupt secure communications for all connected users and systems (Feedly, Debian Advisory).
As of the time of reporting, there are no known public proof-of-concept exploits, no evidence of in-the-wild exploitation, and no threat actor attribution associated with CVE-2026-78131 (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires the ability to initiate or influence a VPN connection or certificate exchange with the target strongSwan instance, which limits the attack surface somewhat. No EPSS score data is currently available given the reserved/early-disclosure status of the CVE.
/var/log/syslog or journalctl -u strongswan) showing repeated certificate parsing errors or warnings related to X.509 attribute certificate identity processing.charon (strongSwan IKE daemon) process observable via top, htop, or system monitoring tools without a corresponding increase in legitimate VPN sessions.dmesg or /var/log/kern.log) terminating the charon process; unexpected VPN daemon restarts.Debian has issued security advisory DSA-6487-1 addressing this vulnerability in strongSwan packages for affected Debian releases; users should apply the updated packages immediately (Debian Advisory). Administrators should update strongSwan to the patched version provided by their distribution (e.g., via apt-get update && apt-get upgrade strongswan on Debian/Ubuntu systems). As a temporary workaround, restricting access to IKE ports (UDP 500, UDP 4500) to trusted IP ranges can reduce exposure. Monitoring memory usage of the charon daemon and configuring automatic restarts can help maintain availability until patching is complete.
The Debian security team published advisory DSA-6487-1 addressing this and related strongSwan issues (Debian Advisory). Linux security news outlets including LinuxSecurity.com and LinuxCompatible.org covered the patches as part of broader daily security roundups (LinuxSecurity, LinuxCompatible). The German Linux security site Pro-Linux.de also reported on the multiple issues in strongSwan (Pro-Linux). No significant social media controversy or notable independent researcher commentary has been observed at this time.
Fix availability across major Linux distributions and their releases.
bookworm
strongswan
sid
strongswan: 6.1.0-1
trixie
strongswan: 6.0.1-6+deb13u7
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."