Our engineers discovered two vulnerabilities (CVE-2026-35330 / CVE-2026-35334) in the “strongSwan” VPN software
Recently, one of our engineers discovered two vulnerabilities in “strongSwan,” an open-source software widely used for building VPNs (Virtual Private Networks).

The following two vulnerabilities were discovered in strongSwan. These vulnerabilities were reported by our engineers to the strongSwan development team, and a security advisory was published on April 22, 2026, concurrent with the release of the fixed version, strongSwan 6.0.6.
Vulnerability in strongSwan (CVE-2026-35330)
Advisory: strongSwan Vulnerability (CVE-2026-35330)
CVE: CVE-2026-35330
CVSSv3: 8.1
CVSSv4: 9.2
CWE: CWE-191(Integer Underflow)
Impact: Critical(Infinite loops, crashes, heap-based buffer overflows, and potential remote code execution)
Scope of Impact: All versions of strongSwan 4.3.6 and later are affected (fixed starting with version 6.0.6)
Attack Vectors: An attack is possible if a malicious user sends a tampered message (attack possible without authentication)
strongSwan の脆弱性(CVE-2026-35334)
Advisory: strongSwan Vulnerability (CVE-2026-35334)
CVE: CVE-2026-35334
CVSSv3: 7.5
CVSSv4: 8.7
CWE: CWE-476(Null Pointer Dereference)
Impact: High(Crashes)
Scope of Impact: All versions of strongSwan 4.3.2 and later are affected (fixed starting with version 6.0.6)
Attack Vectors: An attack is possible if a malicious user distributes tampered communications (attack possible without authentication)
What is strongSwan?
strongSwan is software for setting up IPsec VPNs. It is used in various environments, including Linux, and supports IKEv1, IKEv2, and various authentication methods.
A VPN is a critical mechanism for securely connecting an organization’s network to the outside world, such as for remote access to corporate networks and connections between branch offices. At the same time, due to its nature, a VPN is often deployed at the boundary with the Internet, making vulnerabilities in the software that constitutes the VPN a significant concern for organizational security.
During our investigation into VPN vulnerabilities, we discovered these two vulnerabilities while conducting a technical analysis of strongSwan.
CVE-2026-35330: Vulnerability in EAP-SIM/AKA Attribute Processing
The first vulnerability involves the handling of EAP-SIM/AKA attributes in libsimaka, a common library module shared by strongSwan’s EAP-SIM and EAP-AKA authentication plugins.
EAP-SIM and EAP-AKA are authentication methods used in IKEv2 for authentication and other purposes.
In this vulnerability, when processing certain EAP-SIM/AKA attributes, cases where the value indicating the attribute header length was 0 were not properly validated. As a result, an integer underflow occurs, which, under certain conditions, can lead to an infinite loop or a heap-based buffer overflow.
Since no authentication is required and arbitrary code can be executed remotely, this vulnerability has been assigned a high CVSS v4 score of 9.2.
CVE-2026-35334: NULL pointer reference in RSA decryption processing
The second issue is a vulnerability related to the RSA decryption process implemented in the strongSwan gmp plugin.
In the gmp plugin, the PKCS#1 v1.5 padding verification and removal process was performed without thoroughly verifying whether the data after RSA decryption was a valid result. As a result, we confirmed that if the RSA decryption result was 0 due to specific input, the subsequent processing would access a NULL pointer, causing the strongSwan process to crash.
If the gmp plugin is loaded, an unauthenticated remote DoS attack against strongSwan is possible.
The Importance of Investigating VPN Vulnerabilities
VPNs are widely used for remote access to corporate networks from outside the company and for connecting networks between different locations.
In particular, VPN gateways are often located at the boundary between the Internet and an organization’s internal network, making them a key target for attackers. If vulnerabilities exist in the VPN product itself, even if communications are protected by authentication and encryption, the implementation of those features could become a new attack vector.
Therefore, when it comes to VPN security, it is important not only to verify settings such as authentication methods and cipher suites, but also to check whether the software that makes up the VPN itself contains any potential vulnerabilities.
While a VPN is one of the key security boundaries for protecting an organization’s network, simply “having a VPN in place” does not guarantee security. VPN devices and software may contain not only configuration errors but also unknown vulnerabilities in their implementation itself, as seen in the recent strongSwan case.
At our company, we are leveraging the insights gained from these research activities to enhance security verification of network perimeters—including VPNs—as well as vulnerability assessments and penetration testing.
We will continue our research into vulnerabilities in software and network devices, and we will apply the insights gained from this research to the research and development of our products and services, as well as to enhancing our customers’ security.
How MUSHIKAGO Can Help You
“MUSHIKAGO,” the hardware-based security testing device we provide, is a tool designed to visualize devices within an organization and identify undiscovered risks from the perspective of actual attacks. Some of our customers are also using its capability to detect zero-day vulnerabilities, as described in this article (this is currently not a standard feature but is available as an optional feature upon consultation).
- Quickly gain visibility into devices within the organization
- Detect security risks on a per-device basis
- No internet connection required; also supports closed environments (factories, OT/ICS)
- Ministry of Economy, Trade and Industry (METI) Record of Selected Domestic Security Products
your company is looking to “gain a detailed understanding of your network and device status,” “verify that your environment is truly free of risks,” or “is considering penetration testing for the first time,” please feel free to contact us.
Click here for more information about MUSHIKAGO or to contact usUSHIKAGO
https://powderkegtech.com/ja/mushikago/
Reference
strongSwan Vulnerability (CVE-2026-35330):https://www.strongswan.org/blog/2026/04/22/strongswan-vulnerability-(cve-2026-35330).html
strongSwan Vulnerability (CVE-2026-35334):https://www.strongswan.org/blog/2026/04/22/strongswan-vulnerability-(cve-2026-35334).html
Archive
- August 2026
- June 2026
- April 2026
- March 2026
- November 2025
- October 2025
- September 2025
- June 2025
- March 2025
- February 2025
- October 2024
- August 2024
- May 2024
- April 2024
- March 2024
- February 2024
- November 2023
- October 2023
- April 2023
- September 2022
- August 2022
- July 2022
- June 2022
- April 2022
- March 2022
- December 2021
- October 2021
- August 2021
