CVE-2026-12245: Nlnetlabs Nsd

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.

Affected products

  • Nlnetlabs Nsd: from 4.13.0, before 4.14.3 (fixed in 4.14.3)

Published 2026-06-25. Last modified 2026-06-26.