CVE-2026-12245
Denial of DNS over TLS service by any DoT client
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
| CWE | CWE-416 |
| Vendor | nlnet labs |
| Product | nsd |
| Published | Jun 25, 2026 |
| Last Updated | Jun 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for nlnet labs nsd
Be the first to know when new unknown vulnerabilities affecting nlnet labs nsd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
NLnet Labs / NSD
4.13.0 < 4.14.3
References
Credits
Qifan Zhang from Palo Alto Networks