CVE-2025-32801: ISC Kea

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and/or place the control sockets in insecure paths. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.

Affected products

  • ISC Kea: from 2.4.0, up to and including 2.4.1; from 2.6.0, up to and including 2.6.2; from 2.7.0, up to and including 2.7.8

Published 2025-05-28. Last modified 2026-06-17.