SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-14957

HIGH · CVSS 7.5 EPSS 0.56% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Libreswan in FIPS mode is vulnerable due to a flaw in the add_decoded_cert() function, which can lead to a denial of service when a remote attacker sends a malformed X.509 certificate, causing the pluto daemon to abort and restart. This issue affects both IKEv1 and IKEv2 protocols, but only in configurations where at least one CA certificate is loaded. Organizations utilizing Libreswan in FIPS mode should prioritize patching this vulnerability to mitigate potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-14957
Severity
HIGH
CVSS
7.5
EPSS
0.56%

Original NVD Description

In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable.