{
  "schema_version": "1.6.0",
  "id": "STRONGSWAN-CVE-2026-35330",
  "aliases": [
    "CVE-2026-35330"
  ],
  "modified": "2026-09-25T10:51:01Z",
  "affected": [
    {
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "4.3.6"
            },
            {
              "fixed": "6.0.6"
            }
          ]
        },
        {
          "type": "GIT",
          "repo": "https://github.com/strongswan/strongswan.git",
          "events": [
            {
              "introduced": "f8330d03953bb35fdaec91cabf6e0fd38dd5a144"
            },
            {
              "fixed": "aa5aaebc33e0f326d8a0dbe01b236f2bfa0e6ea1"
            }
          ]
        }
      ]
    }
  ],
  "database_specific": {
    "package": "strongswan"
  },
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://strongswan.org/security/CVE-2026-35330.html"
    },
    {
      "type": "WEB",
      "url": "https://download.strongswan.org/security/CVE-2026-35330"
    }
  ],
  "published": "2026-04-22T12:00:00Z",
  "summary": "A vulnerability in libsimaka related to the processing of certain EAP-SIM/AKA attributes was discovered that can result in an infinite loop or a heap-based buffer overflow and potentially remote code execution.",
  "credits": [
    {
      "name": "Lukas Johannes Moeller",
      "type": "FINDER"
    },
    {
      "name": "Ryo Shimada",
      "type": "FINDER"
    },
    {
      "name": "@DCWebGuy",
      "type": "FINDER"
    }
  ]
}
