PoC Archive PoC Archive

tag

Resolver

  • CVE-2026-40701 web MEDIUM 6.3

    nginx Resolver Use-After-Free in OCSP Stapling (CVE-2026-40701)

    nginx's resolver contains a use-after-free that is reachable when a server is configured with sslstapling on;, sslstaplingverify on;, and a resolver directive — the combination that causes nginx to perform DNS resolution of the OCSP responder hostname on the…

    Patched 2026-07-05
  • None assigned as of 2026-07-03 network HIGH

    c-ares TCP ares_getaddrinfo() Use-After-Free Code Execution

    c-ares's aresgetaddrinfo() path over DNS-over-TCP with EDNS enabled contains a use-after-free reachable when a malicious or compromised DNS server sends two responses for the same query ID in a single TCP read — the first a FORMERR without OPT data…

    Unverified 2026-07-03