CVE-2026-78130

strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.

  • Published Sep 11, 2026
  • CVSS 7.5 high
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-78130 at the National Vulnerability Database