
CVE-2026-27854 An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In s… https://www.cve.org/CVERecord?id=CVE-2026-27854
Post summary
CVE-2026‑27854 is a use‑after‑free vulnerability in DNSdist that can be triggered by crafted DNS queries using custom Lua code, with no evidence of active exploitation, patches, or PoC provided.
