CVE-2026-66374: Nic Knot Resolver
High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.
Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.
Affected products
- Nic Knot Resolver: before 6.4.1 (fixed in 6.4.1)
Published 2026-07-25. Last modified 2026-07-30.