CVE-2026-27831
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
26/02/2026
Last modified:
27/02/2026
Description
rldns is an open source DNS server. Version 1.3 has a heap-based out-of-bounds read that leads to denial of service. Version 1.4 contains a patch for the issue.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/bluedragonsecurity/rldns-1.3-heap-out-of-bounds-vulnerability-fixed-in-rldns-1.4
- https://github.com/bluedragonsecurity/rldns/security/advisories/GHSA-fv38-45j4-g9x4
- https://github.com/bluedragonsecurity/rldns_archives/blob/main/diff/rldns-1.4.diff
- https://medium.com/@w1sdom/heap-based-buffer-over-read-vulnerability-in-rldns-1-3-5da3bccdc031
- https://github.com/bluedragonsecurity/rldns/security/advisories/GHSA-fv38-45j4-g9x4



