A vulnerability in libcharon related to the handling of CREATE_CHILD_SA requests on unestablished IKE SAs was discovered in strongSwan that can result in the creation of a usable Child SA before authentication completes. All versions since 5.9.7 are affected.