← Vulnerability feed

Vulnerability record · CVE-2026-12245 · published 25 June 2026

CVE-2026-12245: Nlnetlabs nsd use after free vulnerability

Nlnetlabs · Nsd

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.

8.7 CVSS 4.0 High EPSS 0.46% · top 62.6% CWE-416 · Use after free
8.7CVSS 4.0 base score
0.46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
26 Jun 2026Last modified by NVD

Description

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-12245 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-12244Nlnetlabs nsd heap-based buffer overflow vulnerabilityIf NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVC…EPSS 0.49%8.2CVE-2026-19538Nlnetlabs nsd authentication bypass by spoofing vulnerabilityThe BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting ove…EPSS 0.23%8.2CVE-2026-18664Nlnetlabs nsd improper access control vulnerabilityWhen ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little end…EPSS 0.26%8.2CVE-2026-19401Nlnetlabs nsd uncontrolled resource consumption vulnerabilityAny remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned numbe…EPSS 0.28%8.2CVE-2026-12490Nlnetlabs nsd improper access control vulnerabilityWhen a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no c…EPSS 0.22%7.5CVE-2016-6173Nlnetlabs nsd vulnerabilityNSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer wi…EPSS 2.9%7.2CVE-2026-12246Nlnetlabs nsd improper input validation vulnerabilityNSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite t…EPSS 0.44%6.9CVE-2026-18916Nlnetlabs nsd vulnerabilityAny remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2026-12245), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.