CVE-2026-78131
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parse
CVSS
3.7
Bajo
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 11 sept 2026 · Última mod.: 11 sept 2026 · CWE-401
Sin historial EPSS suficiente todavía.
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-781273.7 BAJ—
———libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.10hCVE-2026-781243.7 BAJ—
———strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.10hCVE-2026-700657.5 ALT66.3%
——20Missing release of memory after effective lifetime in Windows DHCP Server allows an unauthorized attacker to deny service over a network.19hCVE-2026-698097.5 ALT63.7%
——19Missing release of memory after effective lifetime in Active Directory Domain Services allows an unauthorized attacker to deny service over a network.3dCVE-2026-697816.5 MED42.3%
——13Missing release of memory after effective lifetime in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacent network.19hCVE-2026-695887.5 ALT66.3%
——20Missing release of memory after effective lifetime in Windows TCP/IP allows an unauthorized attacker to deny service over a network.3d