Wiz Agents & Workflows are here

CVE-2021-21323
NixOS vulnerability analysis and mitigation

Overview

Brave browser, an open-source web browser focused on privacy and security, contained a vulnerability in versions 1.17.73-1.20.103 where the CNAME adblocking feature accidentally initiated DNS requests that bypassed the Brave Tor proxy. The vulnerability was discovered in early 2021 and was fixed in version 1.20.108 (GitHub Advisory).

Technical details

The vulnerability was introduced with the CNAME adblocking feature added in Brave 1.17.73. When users had adblocking enabled in Tor windows, DNS requests from CNAME adblocking would leak to their DNS provider instead of being routed through the Tor network. Other DNS requests not initiated by CNAME adblocking would still go through Tor as expected (GitHub Advisory).

Impact

The vulnerability compromised user privacy by leaking DNS requests from Tor windows to the user's DNS provider, potentially revealing browsing activity that was intended to be anonymous through Tor. This affected users who had both adblocking enabled and were using Tor windows (GitHub Advisory).

Mitigation and workarounds

The issue was fixed in Brave version 1.20.108 by disabling CNAME adblocking for Tor windows. This solution was implemented after considering various approaches including routing DoH through Tor, which was deemed too complex due to potential DNS and proxy code looping issues (GitHub PR).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-30892HIGH7.8
  • NixOSNixOS
  • crun
NoYesMar 26, 2026
CVE-2026-33223MEDIUM5.4
  • NixOSNixOS
  • nats-server
NoYesMar 25, 2026
CVE-2026-33222MEDIUM4.9
  • NixOSNixOS
  • rke2-runtime-fips-1.35
NoYesMar 25, 2026
CVE-2026-33249MEDIUM4.3
  • NixOSNixOS
  • telegraf-1.37
NoYesMar 25, 2026
CVE-2026-33248MEDIUM4.2
  • NixOSNixOS
  • rke2-runtime-1.34
NoYesMar 25, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management