Libreswan Project
First CVE: Mar 11, 2024Active for: 2 years
5
CVEs Published
More CVEs Published than 15% of tracked CNAs
2.5
Avg CVEs / Year
More Avg CVEs / Year than 16% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 23% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Libreswan Project as a CNA, 80.0% affect products that Libreswan Project develops as a vendor.
80.0%
20.0%
Self-reported: 4Third-party: 1
Of all the CVEs published that affect products developed by Libreswan Project, 16.7% are self-published by Libreswan Project as a CNA.
16.7%
83.3%
Self-published: 4Published by other CNAs: 20
Trends Over Time
The number and severity of CVEs published by Libreswan Project over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2024
2 years ago
Most Recent CVE
Jul 2, 2026
22 days ago
Top CVEs
All CVEs published by Libreswan Project as a CNA, regardless of affected vendor or product.
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-12413HIGH An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_inc | Jul 2, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-50721MEDIUM Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was en | Jul 2, 2026 | 5.9 | 32 | NO | NO |
CVE-2026-50722MEDIUM Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded u | Jul 2, 2026 | 5.9 | 32 | NO | NO |
CVE-2024-3652MEDIUM The Libreswan Project was notified of an issue causing libreswan to restart when using IKEv1 without specifying an esp= line. When the peer requests AES-GMAC, libreswan's default p | Apr 11, 2024 | 6.5 | 22 | NO | NO |
CVE-2024-2357MEDIUM The Libreswan Project was notified of an issue causing libreswan to restart under some IKEv2 retransmit scenarios when a connection is configured to use PreSharedKeys (authby=secre | Mar 11, 2024 | 6.5 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA5 CVEs
80%
20%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (60.0%)
High2 (40.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (40.0%)
High0 (0.0%)
None3 (60.0%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Libreswan Project as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Libreswan Project as a CNA — matched by CVE ID, not by organization name.