CVE-2026-78124

Summary

strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.

Affected Software

VendorProductVersion RangeStatus
strongSwanstrongSwan5.0.2 < 6.1.0affected

Weaknesses

  • CWE-401: CWE-401 Missing Release of Memory after Effective Lifetime

References