Input validation error in Gaia - CVE-2026-48132
Published: May 28, 2026
Gaia
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in IKE packet processing when handling specially crafted NAT-T traffic over 4500/UDP. A remote attacker can send a specially crafted packet to cause a denial of service.
The issue causes the VPN processing service to terminate unexpectedly, resulting in a temporary interruption of VPN negotiations and traffic.