CVE-2026-58218
MEDIUMDescription
A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejected. A remote, unauthenticated attacker can exploit this behavior by sending a large number of TKEY requests with arbitrary names, exhausting the cache and evicting legitimate TKEY entries. This can prevent legitimate TSIG authentication for signed DNS queries, resulting in a denial of service.
Is your site exposed to CVE-2026-58218?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-58218? +
How severe is CVE-2026-58218? +
How do I check if I'm vulnerable to CVE-2026-58218? +
Related Vulnerabilities
When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of …
In mlflow/mlflow version 2.17.2, the `/graphql` endpoint is vulnerable to a denial of service attack. An attacker can create large …
Insufficient resource pool in Windows Kerberos allows an unauthorized attacker to deny service over a network.
An unauthenticated remote attacker can exploit a denial-of-service vulnerability in the device's web server functionality by sending a specially crafted …
ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected …
Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable …