
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-78132 is a denial-of-service vulnerability in strongSwan's x509 plugin caused by an infinite loop when parsing the ietfAttrSyntax ASN.1 type in X.509 attribute certificates. The CVE is currently in "Reserved" status with limited published details. It affects strongSwan and has been estimated as Medium severity by Feedly's analysis (Feedly). Debian has issued a security announcement addressing this issue (Debian Security).
The root cause is improper handling of the ietfAttrSyntax ASN.1 type within strongSwan's x509 plugin, which triggers an infinite loop during certificate parsing (CWE-835: Loop with Unreachable Exit Condition). An attacker can exploit this by supplying a specially crafted X.509 attribute certificate to a vulnerable strongSwan instance, causing the parsing routine to loop indefinitely. No authentication appears to be required if the attacker can present a certificate during an IKE/TLS handshake, making this potentially remotely exploitable (Feedly, Debian Security).
Successful exploitation causes a denial of service by locking the strongSwan process in an infinite loop, rendering the VPN gateway or IPsec endpoint unresponsive. This affects availability of network connectivity for all users relying on the affected strongSwan instance. There is no indication of confidentiality or integrity impact based on currently available information (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2026-78132 as of the time of this report (Feedly). The CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. Nessus detection plugins (IDs 343484 and 343498) have been published by Tenable, enabling vulnerability scanning (Tenable, Tenable). No EPSS score or threat actor attribution is currently available.
Apply the vendor-supplied patches referenced in the Debian Security Announcement for strongSwan (Debian Security). Users should update strongSwan to the patched version provided by their distribution or the upstream strongSwan project as soon as it becomes available. As a temporary workaround, consider restricting which certificate types are accepted or disabling attribute certificate processing if not required by your deployment. Monitor official strongSwan and distribution advisories for specific patched version numbers (AUSCERT).
The vulnerability was covered in a Linux security roundup noting patches hitting strongSwan alongside PostgreSQL and 389 Directory Server across major distributions (LinuxCompatible). German Linux security outlet Pro-Linux.de also reported on multiple issues in strongSwan including this vulnerability (Pro-Linux). Community reaction appears measured given the Medium severity estimate and lack of known active exploitation.
Fix availability across major Linux distributions and their releases.
bookworm
strongswan
sid
strongswan: 6.1.0-1
trixie
strongswan: 6.0.1-6+deb13u7
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."