CVE-2026-12245
Denial of DNS over TLS service by any DoT client
Description
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
INFO
Published Date :
June 25, 2026, 5:24 a.m.
Last Modified :
June 25, 2026, 5:24 a.m.
Remotely Exploit :
Yes !
Source :
NLnet Labs
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 4.0 | HIGH | 206fc3a0-e175-490b-9eaa-a5738056c9f6 | ||||
| CVSS 4.0 | HIGH | [email protected] |
Solution
- Update NSD to a version that addresses the memory corruption.
- Apply vendor patches for TLS error handling.
- Restart the affected server process.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-12245 vulnerability anywhere in the article.