Improper Handling of Case Sensitivity in strongSwan - CVE-2026-35331

 

Improper Handling of Case Sensitivity in strongSwan - CVE-2026-35331

Published: September 22, 2026


Vulnerability identifier: #VU151575
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-35331
CWE-ID: CWE-178
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to authenticate with certificates that violate excluded X.509 name constraints.

The vulnerability exists due to improper handling of case sensitivity in the constraints plugin when validating X.509 name constraints. A remote user can vary the case of a certificate identity to authenticate with a certificate that violates excluded name constraints.

Only deployments using excluded name constraints are vulnerable.


Affected software

strongSwan
Debian Linux
Fedora
strongswan (Debian package)
strongswan

How to mitigate CVE-2026-35331

Install security update from vendor's website.

strongSwan - update to 6.0.6
strongswan (Debian package) - addressed in versions 5.9.8-5+deb12u4, 6.0.1-6+deb13u5
strongswan - addressed in versions 6.0.6-1.el8, 6.0.6-1.el9, 6.0.6-1.el10_3, 6.0.6-2.fc44, 6.0.6-3.fc43, 6.0.7-2.fc43

External References

Related Security Bulletins