CVE-2024-36587: Dnscrypt Dnscrypt-Proxy

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Insecure permissions in DNSCrypt-proxy v2.0.0alpha9 to v2.1.5 allows non-privileged attackers to escalate privileges to root via overwriting the binary dnscrypt-proxy.

Affected products

  • Dnscrypt Dnscrypt-Proxy: from v2.0.0alpha9, up to and including v2.1.5

Published 2024-06-13. Last modified 2026-06-17.