Improper Handling of Case Sensitivity in strongSwan - CVE-2026-35331
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote user to authenticate with certificates that violate excluded X.509 name constraints.
The vulnerability exists due to improper handling of case sensitivity in the constraints plugin when validating X.509 name constraints. A remote user can vary the case of a certificate identity to authenticate with a certificate that violates excluded name constraints.
Only deployments using excluded name constraints are vulnerable.
Affected software
Debian Linux
Fedora
strongswan (Debian package)
strongswan
How to mitigate CVE-2026-35331
strongswan (Debian package) - addressed in versions 5.9.8-5+deb12u4, 6.0.1-6+deb13u5
strongswan - addressed in versions 6.0.6-1.el8, 6.0.6-1.el9, 6.0.6-1.el10_3, 6.0.6-2.fc44, 6.0.6-3.fc43, 6.0.7-2.fc43