Kea
Vendor:
First CVE: Dec 22, 2015 · Active for 10 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 74% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Kea over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 22, 2015
10 years ago
Most Recent CVE
Mar 25, 2026
120 days ago
CVE Severity & Scoring
Kea10 CVEs
50%
50%
All CVEs352,101 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (30.0%)
Network5 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (20.0%)
Attack Complexity
Low9 (90.0%)
High1 (10.0%)
Unknown0 (0.0%)
User Interaction
None10 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (20.0%)
High0 (0.0%)
None8 (80.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-3608HIGH Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving da | Mar 25, 2026 | 7.5 | 31 | NO | NO |
CVE-2025-11232HIGH To trigger the issue, three configuration parameters must have specific settings: "hostname-char-set" must be left at the default setting, which is "[^A-Za-z0-9.-]"; "hostname-char | Oct 29, 2025 | 7.5 | 27 | NO | NO |
CVE-2018-5739HIGH An extension to hooks capabilities which debuted in Kea 1.4.0 introduced a memory leak for operators who are using certain hooks library facilities. In order to support multiple re | Jan 16, 2019 | 7.5 | 25 | NO | NO |
CVE-2025-32801HIGH Kea configuration and API directives can be used to load a malicious hook library. Many common configurations run Kea as root, leave the API entry points unsecured by default, and | May 28, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-40779HIGH If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4` process will abort with an assertion fail | Aug 27, 2025 | 7.5 | 22 | NO | NO |
CVE-2019-6474MEDIUM A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases which are rejected as invalid when the server | Oct 16, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-6472MEDIUM A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure. Versions affected: 1.4.0 to 1.5.0, 1.6.0-beta1, and 1. | Oct 16, 2019 | 6.5 | 22 | NO | NO |
CVE-2025-32802MEDIUM Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea. Many common configurations run Kea as root, leave the API ent | May 28, 2025 | 6.1 | 19 | NO | NO |
CVE-2015-8373MEDIUM The kea-dhcp4 and kea-dhcp6 servers 0.9.2 and 1.0.0-beta in ISC Kea, when certain debugging settings are used, allow remote attackers to cause a denial of service (daemon crash) vi | Dec 22, 2015 | 6.8 | 19 | NO | NO |
CVE-2025-32803MEDIUM In some cases, Kea log files or lease files may be world-readable.
This issue affects Kea versions 2.4.0 through 2.4.1, 2.6.0 through 2.6.2, and 2.7.0 through 2.7.8. | May 28, 2025 | 4.0 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Kea
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6.0 | 2 | 6.5 | 0.8% | 0 | 0 |
| 1.4.0 | 1 | 7.5 | 1.9% | 0 | 0 |
| 1.0.0 | 1 | 6.8 | 3.7% | 0 | 0 |
| 0.9.2 | 1 | 6.8 | 3.7% | 0 | 0 |