PoC Archive PoC Archive

tag

Edns

  • CVE-2026-4893 network MEDIUM

    dnsmasq EDNS Client Subnet (ECS) Response Validation Bypass (CVE-2026-4893)

    This PoC demonstrates that dnsmasq, when configured with EDNS Client Subnet (ECS, RFC 7871) via add-subnet, will accept an upstream DNS response carrying an ECS option whose subnet does not match the subnet dnsmasq originally sent in the query. The included…

    Patched 2026-07-05
  • None assigned as of 2026-07-03 network HIGH

    c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution

    c-ares's aresgetaddrinfo() path over DNS-over-TCP with EDNS enabled contains a use-after-free reachable when a malicious or compromised DNS server sends two responses for the same query ID in a single TCP read — the first a FORMERR without OPT data…

    Unverified 2026-07-03