CVE-2026-42387
Insufficient input validation in ZoneToCache
Description
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.
INFO
Published Date :
June 25, 2026, 12:59 p.m.
Last Modified :
June 25, 2026, 12:59 p.m.
Remotely Exploit :
Yes !
Source :
OX
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | MEDIUM | 8ce71d90-2354-404b-a86e-bec2cc4e6981 | ||||
| CVSS 3.1 | MEDIUM | MITRE-CVE | ||||
| CVSS 3.1 | MEDIUM | [email protected] |
Solution
- Apply software updates to fix input validation.
- Ensure zone data is validated before caching.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-42387 vulnerability anywhere in the article.