Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to libreswan 5.3.2 or later. Patches for libreswan 4.15 and 5.3 are available at https://libreswan.org/security/CVE-2026-14957/
Vendor Workaround
No workaround is available unless one is willing to disable FIPS mode. If libreswan is only using PreSharedKey (PSK) authentication and the NSS database contains no CA certificates, CERT payloads are ignored and libreswan is not vulnerable.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if the RSA exponent is set to 0. A remote attacker can send a malformed X.509 certificate in a CERT payload to trigger the assertion, causing the pluto daemon to abort and restart. Continued exploitation causes a denial of service. No remote code execution is possible. Both IKEv1 and IKEv2 are affected. The vulnerability is only exploitable when both the OS and libreswan are running in FIPS mode and at least one CA certificate is loaded. The CERT payload is processed before peer authentication, so no credentials are needed to exploit this. Configurations using only PreSharedKey (PSK) authentication with no CA certificates loaded in the NSS database are not vulnerable. |
| Title | libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process | FIPS mode assertion failure via malicious CERT payload |
| Weaknesses | CWE-252 |
Tue, 21 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Libreswan
Libreswan libreswan |
|
| Vendors & Products |
Libreswan
Libreswan libreswan |
Sat, 18 Jul 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | No description is available for this CVE. | |
| Title | libreswan: badly formatted X.509 certificate can cause an assertion failure that crashes the daemon process | |
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: libreswan
Published:
Updated: 2026-09-02T13:00:19.908Z
Reserved: 2026-07-07T13:39:23.932Z
Link: CVE-2026-14957
Updated: 2026-09-02T13:00:15.062Z
Status : Received
Published: 2026-09-02T03:16:47.490
Modified: 2026-09-02T13:17:07.100
Link: CVE-2026-14957
OpenCVE Enrichment
Updated: 2026-09-02T04:15:05Z
