Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-50721 Details

Description

Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge the SIG payload when small public exponents are being used (e.g., e=3), which could lead to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the SIG payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of remote IKE peers are not affected.

Metrics

CVSS 3.x Severity and Vector Strings:

CNA: Libreswan ProjectCVSS-B:8.1 HIGHVector:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://libreswan.org/security/CVE-2026-50721/ Libreswan ProjectVendor Advisory
https://libreswan.org/security/CVE-2026-50721/CVE-2026-50721.txt Libreswan ProjectVendor Advisory
https://libreswan.org/security/CVE-2026-50722/CVE-2026-50722.txt Libreswan ProjectVendor Advisory
https://www.rfc-editor.org/rfc/rfc2313 Libreswan ProjectTechnical Description

Weakness Enumeration

CWE-IDCWE NameSource
CWE-347Improper Verification of Cryptographic SignatureLibreswan Project
CWE-617Reachable AssertionLibreswan Project

Affected Products

ProductVersions
libreswan libreswan
< 5.3.1

CPE

  • cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-50721
NVD Published Date:
Jul 2, 2026
NVD Last Modified:
Jul 9, 2026
Source:
Libreswan Project
CVE-2026-50721 Details - Not Deferred