๐Ÿ” CVE Alert

CVE-2026-12245

UNKNOWN 0.0

Denial of DNS over TLS service by any DoT client

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.

CWE CWE-416
Vendor nlnet labs
Product nsd
Published Jun 25, 2026
Last Updated Jun 25, 2026
Stay Ahead of the Next One

Get instant alerts for nlnet labs nsd

Be the first to know when new unknown vulnerabilities affecting nlnet labs nsd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

NLnet Labs / NSD
4.13.0 < 4.14.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
nlnetlabs.nl: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12245.txt

Credits

Qifan Zhang from Palo Alto Networks