|
1491
|
7.5 |
HIGH
Network
|
-
|
-
|
A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.
|
CWE-349
Acceptance of Extraneous Untrusted Data With Trusted Data
|
CVE-2026-33612
|
2026-06-26 01:00 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1492
|
3.7 |
LOW
Network
|
-
|
-
|
An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The pr…
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-40011
|
2026-06-26 01:00 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1493
|
3.7 |
LOW
Network
|
-
|
-
|
An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.
|
CWE-705
Incorrect Control Flow Scoping
|
CVE-2026-40208
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1494
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a…
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2026-40209
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1495
|
4.8 |
MEDIUM
Network
|
-
|
-
|
An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash.
|
CWE-126
Buffer Over-read
|
CVE-2026-40210
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1496
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-40211
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1497
|
3.7 |
LOW
Network
|
-
|
-
|
An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend …
|
CWE-115
Misinterpretation of Input
|
CVE-2026-42004
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1498
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.
|
CWE-20
Improper Input Validation
|
CVE-2026-42390
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1499
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-52690
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1500
|
4.7 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.…
|
CWE-346
Origin Validation Error
|
CVE-2026-13034
|
2026-06-26 00:23 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|