A vulnerability in strongSwan before version 6.0.7 involves mishandling of identity parsing and cloning. Specifically, parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned. This flaw triggers a double-free condition when the duplicate identities are destroyed. Double-free vulnerabilities can lead to memory corruption, potential crashes, or arbitrary code execution. The issue has been addressed in strongSwan version 6.0.7. Users are advised to upgrade to the patched version immediately. The vulnerability is tracked as CVE-2026-47895 and is considered high severity.