https://kb.isc.org/docs/cve-2026-3608
Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp-ddns, kea-dhcp4, or kea-dhcp6 daemons over any configured API socket or HA listener can cause the receiving daemon to exit with a stack overflow error.
It is addressed in https://gitlab.isc.org/isc-projects/kea/-/merge_requests/2983