Security Advisories

Published strongSwan Vulnerabilities / CVEs

Please follow our security policy if you find or suspect a vulnerability in strongSwan.

Machine-readable OSV records for each CVE are available, with an index of all records.

To find your installed version, run swanctl --version or ipsec version.

Date Advisory Since Fixed Links
2026-09-07 CVE-2026-78135
A vulnerability in libcharon related to the handling of CREATE_CHILD_SA requests on unestablished IKE SAs can result in the creation of a usable Child SA before authentication completes.
5.9.7 6.1.0 Patch OSV
2026-09-07 CVE-2026-78134
A vulnerability in the eap-peap and eap-ttls plugins related to the propagation of authentication details from inner EAP methods can result in incorrect identity binding and potential authorization bypass.
4.5.0 6.1.0 Patch OSV
2026-09-07 CVE-2026-78133
A vulnerability in libcharon related to the handling of IKEv2 rekeying collisions can result in a use-after-free and potentially remote code execution.
6.0.0 6.1.0 Patch OSV
2026-09-07 CVE-2026-78132
A vulnerability in the x509 plugin related to the parsing of the ietfAttrSyntax ASN.1 type in X.509 attribute certificates can lead to a denial of service.
5.1.3 6.1.0 Patch OSV
2026-09-07 CVE-2026-78131
A vulnerability in the x509 plugin related to the parsing of identities in X.509 attribute certificates can lead to a denial of service via memory exhaustion.
4.2.0 6.1.0 Patch OSV
2026-09-07 CVE-2026-78130
A vulnerability in the x509 plugin related to the verification of X.509 attribute certificates can lead to a denial of service.
4.2.0 6.1.0 Patch OSV
2026-09-07 CVE-2026-78129
A vulnerability in libstrongswan related to the processing of encrypted PKCS#7 containers can result in a denial of service.
4.6.2 6.1.0 Patch OSV
2026-09-07 CVE-2026-78127
A vulnerability in libcharon related to the logging of IKE messages can result in a denial of service via memory exhaustion.
4.1.2 6.1.0 Patch OSV
2026-09-07 CVE-2026-78126
A vulnerability in the eap-aka plugin related to processing an unexpected AKA-Synchronization-Failure message can result in a crash.
4.1.10 6.1.0 Patch OSV
2026-09-07 CVE-2026-78124
A vulnerability in the openssl plugin related to the enumeration of certificates in PKCS#7 containers can result in memory leaks.
5.0.2 6.1.0 Patch OSV
2026-09-07 CVE-2026-78123
A vulnerability in the openssl plugin related to the processing of PKCS#7 containers can result in a crash.
5.0.2 6.1.0 Patch OSV
2026-06-08 CVE-2026-47895
A vulnerability in libstrongswan related to the cloning of certain identities can result in a double-free and potentially remote code execution.
4.3.3 6.0.7 Patch OSV
2026-04-22 CVE-2026-35334
A vulnerability in the gmp plugin related to RSA decryption can result in a crash.
4.3.2 6.0.6 Patch OSV
2026-04-22 CVE-2026-35333
A vulnerability in libradius related to the processing of RADIUS attributes can result in an infinite loop or an out-of-bounds read that may cause a crash.
4.2.14 6.0.6 Patch OSV
2026-04-22 CVE-2026-35332
A vulnerability in libtls related to the processing of ECDH public values in TLS < 1.3 can result in a crash.
4.5.0 6.0.6 Patch OSV
2026-04-22 CVE-2026-35331
A vulnerability in the constraints plugin related to the processing of X.509 name constraints can allow authentication with certificates that violate the constraints.
4.5.1 6.0.6 Patch OSV
2026-04-22 CVE-2026-35330
A vulnerability in libsimaka related to the processing of certain EAP-SIM/AKA attributes can result in an infinite loop or a heap-based buffer overflow and potentially remote code execution.
4.3.6 6.0.6 Patch OSV
2026-04-22 CVE-2026-35329
A vulnerability in libstrongswan and the pkcs7 plugin related to the processing of encrypted PKCS#7 containers can result in a crash.
5.0.2 6.0.6 Patch OSV
2026-04-22 CVE-2026-35328
A vulnerability in libtls related to the processing of the supported_versions extension in TLS can result in an infinite loop.
5.9.2 6.0.6 Patch OSV
2026-03-23 CVE-2026-25075
A vulnerability in the eap-ttls plugin related to processing EAP-TTLS AVPs can result in resource exhaustion or a crash.
4.5.0 6.0.5 Patch OSV
2025-12-12 CVE-2025-9615
A vulnerability in the NetworkManager plugin that potentially allows using credentials of other local users.
4.2.7 6.0.4 Patch OSV
2025-10-27 CVE-2025-62291
A vulnerability in the eap-mschapv2 plugin related to processing Failure Request packets on the client can result in a heap-based buffer overflow and potentially remote code execution.
4.2.12 6.0.3 Patch OSV
2024-05-13 CVE-2022-4967
This advisory reclassifies an old bug in our TLS library as a potential authorization bypass vulnerability in order to get the fix applied to affected distribution packages. The bug is contained in versions 5.9.2 through 5.9.5 and was fixed with 5.9.6, which was released in August 2022.
5.9.2 5.9.6 Patch OSV
2023-11-20 CVE-2023-41913
A vulnerability in charon-tkm related to processing DH public values can result in a buffer overflow and potentially remote code execution.
5.3.0 5.9.12 Patch OSV
2023-03-02 CVE-2023-26463
A vulnerability related to certificate verification in TLS-based EAP methods results in a denial of service but possibly even remote code execution.
5.9.8 5.9.10 Patch OSV
2022-10-03 CVE-2022-40617
A vulnerability related to online certificate revocation checking can lead to a denial-of-service attack.
4.0.0 5.9.8 Patch OSV
2022-01-24 CVE-2021-45079
A vulnerability in the EAP client implementation.
4.1.2 5.9.5 Patch OSV
2021-10-18 CVE-2021-41991
A denial-of-service vulnerability in the in-memory certificate cache.
4.2.10 5.9.4 Patch OSV
2021-10-18 CVE-2021-41990
A denial-of-service vulnerability in the gmp plugin.
5.6.1 5.9.4 Patch OSV
2018-10-01 CVE-2018-17540
A denial-of-service vulnerability in the gmp plugin.
5.7.0 5.7.1 Patch OSV
2018-09-24 CVE-2018-16152
A potential authorization bypass vulnerability in the gmp plugin.
4.0.0 5.7.0 Patch OSV
2018-09-24 CVE-2018-16151
A potential authorization bypass vulnerability in the gmp plugin.
4.0.0 5.7.0 Patch OSV
2018-05-28 CVE-2018-5388
A denial-of-service vulnerability in the stroke plugin.
4.0.0 5.6.3 Patch OSV
2018-05-28 CVE-2018-10811
A denial-of-service vulnerability in the IKEv2 key derivation.
5.0.1 5.6.3 Patch OSV
2018-02-19 CVE-2018-6459
A denial-of-service vulnerability in the parser for RSASSA-PSS signatures.
5.6.1 5.6.2 Patch OSV
2017-08-14 CVE-2017-11185
A denial-of-service vulnerability in the gmp plugin.
4.0.0 5.6.0 Patch OSV
2017-05-30 CVE-2017-9023
A denial-of-service vulnerability in the x509 plugin.
4.0.0 5.5.3 Patch OSV
2017-05-30 CVE-2017-9022
A denial-of-service vulnerability in the gmp plugin.
4.4.0 5.5.3 Patch OSV
2015-11-16 CVE-2015-8023
An authentication bypass vulnerability in the eap-mschapv2 plugin.
4.2.12 5.3.4 Patch OSV
2015-06-08 CVE-2015-4171
An information leak vulnerability that affects certain IKEv2 setups.
4.3.0 5.3.2 Patch OSV
2015-06-01 CVE-2015-3991
A denial-of-service and potential remote code execution vulnerability triggered by crafted IKE messages.
5.2.2 5.3.1 Patch OSV
2015-01-05 CVE-2014-9221
A DoS vulnerability triggered by an IKEv2 Key Exchange payload containing DH group 1025.
4.5.0 5.2.2 Patch OSV
2014-05-05 CVE-2014-2891
A DoS vulnerability triggered by crafted ID payloads.
4.3.3 5.1.2 Patch OSV
2014-04-14 CVE-2014-2338
An authentication bypass vulnerability can be triggered by rekeying an unestablished IKEv2 SA while it gets actively initiated.
4.0.7 5.1.3 Patch OSV
2013-11-01 CVE-2013-6076
A DoS vulnerability triggered by crafted IKEv1 fragmentation payloads in the IKE daemon charon.
5.0.2 5.1.1 Patch OSV
2013-11-01 CVE-2013-6075
A DoS vulnerability and potential authorization bypass triggered by a crafted ID_DER_ASN1_DN ID payload.
4.3.3 5.1.1 Patch OSV
2013-08-01 CVE-2013-5018
A DoS vulnerability in strongSwan triggered by crafted XAuth usernames and EAP identities.
5.0.3 5.1.0 Patch OSV
2013-05-13 CVE-2013-2054
A vulnerability in the atodn() function used by the legacy pluto daemon can lead to a remote buffer overflow when parsing DNS TXT records in manually configured Opportunistic Encryption setups.
2.0.0 4.3.5 Patch OSV
2013-04-30 CVE-2013-2944
An authentication bypass vulnerability in the openssl plugin that allows authentication with an empty, zeroed or otherwise invalid ECDSA signature.
4.3.5 5.0.4 Patch OSV
2012-05-31 CVE-2012-2388
An authentication bypass vulnerability in the gmp plugin that allows authentication with an empty or zeroed RSA signature.
4.2.0 4.6.4 Patch OSV
2010-07-28 CVE-2010-2628
The IKE daemon does not properly check the return values of snprintf calls, which allows remote attackers to execute arbitrary code via crafted certificate or identity data that triggers buffer overflows.
4.3.3 4.4.1 Patch OSV
2009-07-06 CVE-2009-2661
The RDN parser vulnerability was not completely fixed in version 4.3.2; further modifications had to be applied to the asn1_length() function.
4.0.0 4.3.3 Patch OSV
2009-06-18 CVE-2009-2185
A denial-of-service vulnerability in the parsing of ASN.1 Relative Distinguished Names (RDNs). Malformed X.509 certificate RDNs can cause the pluto and charon IKE daemons to crash and restart.
4.0.0 4.3.2 Patch OSV
2009-05-22 CVE-2009-1958
A denial-of-service vulnerability where receiving a malformed IKE_AUTH request with either a missing TSi or TSr traffic selector payload causes a crash of the IKEv2 charon daemon while dereferencing a NULL pointer.
4.1.0 4.3.1 Patch OSV
2009-05-08 CVE-2009-1957
A denial-of-service vulnerability where receiving a malformed IKE_SA_INIT request leaves an incomplete state that causes a crash of the IKEv2 charon daemon while dereferencing a NULL pointer if a subsequent CREATE_CHILD_SA is received.
4.1.0 4.3.1 Patch OSV
2009-03-21 CVE-2009-0790
A denial-of-service vulnerability where a DPD R_U_THERE or R_U_THERE_ACK NOTIFY message (Dead Peer Detection) not related to an existing ISAKMP Security Association causes an immediate crash of the IKEv1 pluto daemon while dereferencing a NULL state pointer.
4.0.0 4.2.14 Patch OSV
2008-09-22 CVE-2008-4551
A denial-of-service vulnerability where an IKE_SA_INIT message with a KE payload containing zeroes only can cause a crash of the IKEv2 charon daemon due to a NULL pointer returned by the mpz_export() function of the GNU Multi Precision (GMP) library.
4.1.8 4.2.7 Patch OSV

"Since" is the first affected release, "Fixed" the release containing the fix. Click a version to see which other advisories affect that version.