CVE-2026-33811
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
CVSS
7.5
High
EPSS
0.8%
p55
KEV
—
Exploit Today
16
0-100
Published: May 7, 2026 · Last modified: Sep 9, 2026 · CWE-415 · CWE-1341
0.8%EPSS · 30 days0.8%
2026-08-122026-09-09
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
- go.devhttps://go.dev/cl/767860
- go.devhttps://go.dev/issue/78803
- groups.google.comhttps://groups.google.com/g/golang-announce/c/qcCIEXso47M
- pkg.go.devhttps://pkg.go.dev/vuln/GO-2026-4981
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22112
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22120
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:22121
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:23262
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:23264
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33120
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33123
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33142
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33150
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:33574
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:34357
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:34359
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:34364
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:35832
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:35993
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:35994
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-875858.8 HIG9.7%
——3Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)20hCVE-2026-799077.8 HIG8.8%
——3Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.22hCVE-2026-819507.8 HIG36.7%
——11Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.23hCVE-2026-800808.8 HIG47.0%
——14Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.1dCVE-2026-775048.8 HIG47.6%
——14Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.1dCVE-2026-774939.8 CRI60.0%
——18Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.1d