Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2026-50722 Details

Description

Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote code execution is not possible. X.509 certificate verifications of the remote IKE peer are not affected.

Metrics

CVSS 3.x Severity and Vector Strings:

CNA: Libreswan ProjectCVSS-B:8.1 HIGHVector:CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://libreswan.org/security/CVE-2026-50721/CVE-2026-50721.txt Libreswan ProjectVendor AdvisoryMailing List
https://libreswan.org/security/CVE-2026-50722/ Libreswan ProjectVendor Advisory
https://libreswan.org/security/CVE-2026-50722/CVE-2026-50722.txt Libreswan ProjectVendor Advisory
https://www.rfc-editor.org/rfc/rfc8017 Libreswan ProjectTechnical Description

Weakness Enumeration

CWE-IDCWE NameSource
CWE-347Improper Verification of Cryptographic SignatureLibreswan Project
CWE-617Reachable AssertionLibreswan Project

Affected Products

ProductVersions
libreswan libreswan
< 5.3.1

CPE

  • cpe:2.3:a:libreswan:libreswan:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

3 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2026-50722
NVD Published Date:
Jul 2, 2026
NVD Last Modified:
Jul 9, 2026
Source:
Libreswan Project
CVE-2026-50722 Details - Not Deferred