THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-33630 (HIGH 7.5) — c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present

[NVD] CVE-2026-33630 (HIGH 7.5) — c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present

mednvdPublished 2026-09-03

CVE-2026-33630 CVSS: 7.5 HIGH Published: 2026-09-03T19:17:27.420

c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channel's internal lookup structures — is present at multiple points in the resend/finish path (timeout

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-33630