AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-13002

MEDIUM · CVSS 4.4

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The dnsmasq service is vulnerable due to a flaw in the dnssec.c library that can be exploited by an attacker controlling a DNSSEC-signed zone, leading to an infinite loop and causing the dnsmasq process to hang. This results in a denial of service for all clients relying on dnsmasq for DNS resolution. Organizations utilizing dnsmasq should prioritize addressing this vulnerability to maintain service availability and prevent disruption.

CVE
CVE-2026-13002
Severity
MEDIUM
CVSS
4.4
EPSS
N/A

Original NVD Description

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls any DNSSEC-signed zone can hang the dnsmasq process with a single crafted response, killing all DNS resolution for its clients.