
CVE-2026-33598 A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache. https://www.cve.org/CVERecord?id=CVE-2026-33598
Post summary
The statement discloses a CVE-2026-33598 that causes an out‑of‑bounds read when custom Lua code calls certain packet‑cache functions, but it provides neither proof‑of‑concept nor patch details.

