Month: July 2026
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time ‘ghost domain’ delegation renewal via glue records
CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use
Information published. Continue reading CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use
CVE-2026-56444 Degradation of resolution service when ‘discard-timeout’ and ‘serve-expired-client-timeout’ are combined in unusual configuration
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
CVE-2026-40691 Packet of death for DNSCrypt over TCP
Information published. Continue reading CVE-2026-40691 Packet of death for DNSCrypt over TCP
