Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33811

Опубликовано: 07 мая 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Версия до 1.25.10 (исключая)
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
Версия от 1.26.0 (включая) до 1.26.3 (исключая)

EPSS

Процентиль: 53%
0.00813
Низкий

7.5 High

CVSS3

Дефекты

CWE-415
CWE-1341

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

CVSS3: 7.5
redhat
3 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

msrc
3 месяца назад

Crash when handling long CNAME response in net

CVSS3: 7.5
debian
3 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME re ...

CVSS3: 7.5
github
3 месяца назад

When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.

EPSS

Процентиль: 53%
0.00813
Низкий

7.5 High

CVSS3

Дефекты

CWE-415
CWE-1341