CVE-2025-32803: ISC Kea
Medium severity, CVSS 4.0. EPSS: 0.2% chance of exploitation in the next 30 days.
In some cases, Kea log files or lease files may be world-readable. This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8.
Affected products
- ISC Kea: from 2.4.0, up to and including 2.4.1; from 2.6.0, up to and including 2.6.2; from 2.7.0, up to and including 2.7.8
Published 2025-05-28. Last modified 2026-06-17.