Cloudflare WARP Client for Windows DNS Query Interception Vulnerability via Unique Local Addresses

Vulnerability

A vulnerability in the Cloudflare WARP client for Windows, prior to version 2023.7.160.0, allows interception of DNS queries under certain network conditions. While the client typically assigns loopback IPv4 addresses for DNS servers, it instead assigns Unique Local Addresses for IPv6 when connected to an IPv6-capable network. This could potentially direct DNS queries to unknown devices on the local network, enabling an attacker to monitor the DNS requests. The issue arises when the device is connected to a rogue Wi-Fi network that supports IPv6 and assigns the same IPv6 address as the WARP client uses for its DNS server.

Impact

Exploitation of this vulnerability could lead to unauthorized interception and viewing of DNS queries made by the affected device.

Remediation

Users can update to WARP Client version 2023.7.160.0 or later. Alternatively, IPv6 support can be disabled on local devices.

Added: Mar 11, 2026, 7:10 PM
Updated: Mar 11, 2026, 7:10 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
0.2
exploitability
3.7
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.