CVE-2026-40719 PUBLISHED

Assigner: mitre
Reserved: 15.04.2026 Published: 15.04.2026 Updated: 15.04.2026

Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor MaraDNS
Product MaraDNS
Versions Default: unknown
  • Version 3.5.0036 is affected

References

Problem Types

  • CWE-670 Always-Incorrect Control Flow Implementation CWE