Dnsmasq is a lightweight DNS and DHCP server widely embedded in home routers, embedded appliances, and Linux distributions, creating a broad installed base despite its narrow product scope. The observed vulnerability profile centers on the DNS and DHCP service logic itself, reflecting the complexity of parsing and state management in network protocols exposed to untrusted input. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dnsmasq over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4892HIGH A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 pa | May 11, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-4890HIGH A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet. | May 11, 2026 | 7.5 | 38 | NO | NO |
CVE-2026-4891HIGH A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet. | May 11, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-5172HIGH A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extra | May 11, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-2291HIGH dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirec | May 11, 2026 | 7.3 | 35 | NO | NO |
CVE-2026-4893MEDIUM An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information. | May 11, 2026 | 5.3 | 27 | NO | NO |
CVE-2006-2017MEDIUM Dnsmasq 2.29 allows remote attackers to cause a denial of service (application crash) via a DHCP client broadcast reply request. | Apr 25, 2006 | 5.0 | 20 | NO | NO |
CVE-2005-0876MEDIUM Off-by-one buffer overflow in Dnsmasq before 2.21 may allow attackers to execute arbitrary code via the DHCP lease file. | May 2, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dnsmasq.
Media articles that mention a CVE ID that affects a product developed by Dnsmasq — matched by CVE ID, not by vendor name.