CVE-2026-40719: High severity MaraDNS MaraDNS Deadwood vulnerability
Published Apr 15, 2026
·Updated
Deadwood in MaraDNS 3.5.0036 allows attackers to exhaust connection slots via a zone whose authoritative nameserver address cannot be resolved.
Affected Software
1 affected component
MaraDNS MaraDNS Deadwood=3.5.0036
Event History
Apr 15, 2026
CVE Published
via MITRE·06:23 AM
Data Sourced
via MITRE·06:23 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-40719?
CVE-2026-40719 is considered a high-severity vulnerability due to its potential to exhaust connection slots.
2
How do I fix CVE-2026-40719?
To fix CVE-2026-40719, update to the latest version of MaraDNS that addresses this vulnerability.
3
What can attackers do with CVE-2026-40719?
Attackers can exploit CVE-2026-40719 to exhaust connection slots, leading to denial of service for legitimate users.
4
Which version of MaraDNS is vulnerable to CVE-2026-40719?
MaraDNS version 3.5.0036 is the only identified version vulnerable to CVE-2026-40719.
5
Is there a workaround for CVE-2026-40719 before updating?
A potential workaround for CVE-2026-40719 is to configure the authoritative nameserver address to ensure it can be resolved.