strongSwan vulnerability

libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behavioral workflow in the IKEv2 state machine. Because CREATE_CHILD_SA requests are mishandled, there can be an authentication bypass.

Published 11 Sep 2026Updated 11 Sep 20262 sources
CVSS 5.6

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.