HIGH7.8CVE-2025-32801Kea configuration and API directives can be used to load a malicious hook library.
from 0
HIGH7.5CVE-2026-3608Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket…
from 0
HIGH7.5CVE-2025-40779If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the client, the `kea-dhcp4`…
from 0
MEDIUM6.1Kea configuration and API directives can be used to overwrite arbitrary files, subject to permissions granted to Kea.
from 0
MEDIUM4.0In some cases, Kea log files or lease files may be world-readable.