CVE-2026-4893: Dnsmasq
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.
Affected products
- Dnsmasq Dnsmasq: before 2.92rel2 (fixed in 2.92rel2)
Published 2026-05-11. Last modified 2026-06-17.