pkg:Alpine/kea

7 total CVEsHIGH2MEDIUM5

✅ Check your installed version

All known vulnerabilities

  • HIGH7.8CVE-2025-32801Kea configuration and API directives can be used to load a malicious hook library.
    from 0, < 2.6.3-r0
  • HIGH7.5CVE-2026-3608Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket…
    from 0, < 2.6.5-r0
  • MEDIUM6.5CVE-2019-6474A missing check on incoming client requests can be exploited to cause a situation where the Kea server's lease storage contains leases whic…
    from 0, < 1.7.2-r0
  • MEDIUM6.5CVE-2019-6473An invalid hostname option can trigger an assertion failure in the Kea DHCPv4 server process (kea-dhcp4), causing the server process to exi…
    from 0, < 1.7.2-r0
  • MEDIUM6.5CVE-2019-6472A packet containing a malformed DUID can cause the Kea DHCPv6 server process (kea-dhcp6) to exit due to an assertion failure.
    from 0, < 1.7.2-r0
  • MEDIUM6.1CVE-2025-32802Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea.
    from 0, < 2.6.3-r0
  • MEDIUM4.0CVE-2025-32803In some cases, Kea log files or lease files may be world-readable.
    from 0, < 2.6.3-r0