- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
Severity across 68 analyzed records
As of 09/11/2026, NLnet Labs recorded 32 security vulnerabilities in the last 90 days across 2 products, including 11 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, unbound had the most security vulnerabilities in the NLnet Labs ecosystem, with 24 vulnerabilities—approximately 75% of the provider's total vulnerabilities during this period.
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-19538Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS | Exploitation statusNot known exploited | FixYes | Affected productNSD | Published08/26/2026 | SeverityHigh |
CVE-2026-19401Remote UDP DoS by sending multiple DNS Cookie options | Exploitation statusNot known exploited | FixYes | Affected productNSD | Published08/26/2026 | SeverityHigh |
CVE-2026-18916Remote TCP DoS by throttling the TCP receive window | Exploitation statusNot known exploited | FixYes | Affected productNSD | Published08/26/2026 | SeverityMedium |
CVE-2026-18664Wrong interpretation of ACL ranges | Exploitation statusNot known exploited | FixYes | Affected productNSD | Published08/26/2026 | SeverityHigh |
CVE-2026-56444Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-56416Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-55991Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-55990Packet of death for a DNSCrypt misconfigured Unbound | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-55973'dns-error-reporting: yes' leads to stack buffer overflow | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityHigh |
CVE-2026-55717'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-55708Privacy/configuration issue when adding local data in views through 'unbound-control' | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityLow |
CVE-2026-54478DNS Cookie bypass when combined with proxy-protocol use | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityLow |
CVE-2026-52863Memory corruption could lead to crash and denial of service | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-50252Possible cache poisoning attack by mapping source port population per thread | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-50251Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-50248BOGUS configured primary hostname accepted for XFR in auth/rpz zones | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-50243'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-50046Possible heap use-after-free in an error path when a DoT forwarded query is jostled out | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-50045'max-global-quota' reset by DNSSEC validation restarts | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-46582A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityLow |
CVE-2026-44690Cross-zone wildcard cache poisoning via RRSIG.labels manipulation | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityHigh |
CVE-2026-44687Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityLow |
CVE-2026-44621Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-42955Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityLow |
CVE-2026-41637Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityLow |
CVE-2026-40691Packet of death for DNSCrypt over TCP | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityHigh |
CVE-2026-32665Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityHigh |
CVE-2026-14586Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/22/2026 | SeverityMedium |
CVE-2026-12490Bypass of client certificate verification with transfer over TLS | Exploitation statusNot known exploited | FixYes | Affected productNSD | Published06/25/2026 | SeverityHigh |
CVE-2026-12246Out of bounds stack write with crafted APL RR | Exploitation statusNot known exploited | FixYes | Affected productNSD | Published06/25/2026 | SeverityHigh |
CVE-2026-12245Denial of DNS over TLS service by any DoT client | Exploitation statusNot known exploited | FixYes | Affected productNSD | Published06/25/2026 | SeverityHigh |
CVE-2026-12244Heap overflow and crash with crafted SVCB RR | Exploitation statusNot known exploited | FixYes | Affected productNSD | Published06/25/2026 | SeverityHigh |
CVE-2026-10846Insufficient verification that responses belong to a query | Exploitation statusNot known exploited | FixYes | Affected productldns | Published06/10/2026 | SeverityHigh |
CVE-2026-49235Routinator crashes on specifically crafted RRDP XML files | Exploitation statusNot known exploited | FixYes | Affected productRoutinator | Published06/08/2026 | SeverityHigh |
CVE-2026-49234Routinator crashes on specifically crafted ASN strings in the API | Exploitation statusNot known exploited | FixYes | Affected productRoutinator | Published06/08/2026 | SeverityHigh |
CVE-2026-49233Routinator cache path traversal using rogue rsync URIs | Exploitation statusNot known exploited | FixYes | Affected productRoutinator | Published06/08/2026 | SeverityHigh |
CVE-2026-49232Routinator exits when accepting an incoming HTTP or RTR connection fails | Exploitation statusNot known exploited | FixYes | Affected productRoutinator | Published06/08/2026 | SeverityHigh |
CVE-2026-44608Use after free and crash under special conditions in RPZ code | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityMedium |
CVE-2026-44390Unbounded name compression in certain cases causes degradation of service | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityMedium |
CVE-2026-42960Possible cache poisoning via promiscuous records for the authority section | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityMedium |
CVE-2026-42959Crash during DNSSEC validation of malicious content | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityHigh |
CVE-2026-42944Heap overflow with multiple NSID, COOKIE, PADDING EDNS options | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityHigh |
CVE-2026-42923Degradation of service with unbounded NSEC3 hash calculations | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityMedium |
CVE-2026-42534Jostle logic bypass degrades resolution performance | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityMedium |
CVE-2026-41292Long list of incoming EDNS options degrades performance | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityMedium |
CVE-2026-40622Another 'ghost domain names' attack variant | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityMedium |
CVE-2026-33278Possible arbitrary code execution during DNSSEC validation | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityCritical |
CVE-2026-32792Packet of death with DNSCrypt | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published05/20/2026 | SeverityMedium |
CVE-2025-11411Possible domain hijacking via promiscuous records in the authority section | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published10/22/2025 | SeverityMedium |
CVE-2025-5994Cache poisoning via the ECS-enabled Rebirthday Attack | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published07/16/2025 | SeverityHigh |
CVE-2025-0638Routinator crashes when illegal characters are present in manifest file names | Exploitation statusNot known exploited | FixYes | Affected productRoutinator | Published01/22/2025 | SeverityHigh |
CVE-2024-8508Unbounded name compression could lead to Denial of Service | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published10/03/2024 | SeverityMedium |
CVE-2024-1931Denial of service when trimming EDE text on positive replies | Exploitation statusNot known exploited | FixYes | Affected productunbound | Published03/07/2024 | SeverityHigh |
CVE-2024-1622Routinator terminates when RTR connection is reset too quickly after opening | Exploitation statusNot known exploited | FixYes | Affected productRoutinator | Published02/26/2024 | SeverityHigh |
CVE-2023-39916Possible path traversal when storing RRDP responses | Exploitation statusNot known exploited | FixYes | Affected productRoutinator | Published09/13/2023 | SeverityCritical |
CVE-2023-39915Crashes on parsing certain invalid RPKI objects | Exploitation statusNot known exploited | FixYes | Affected productRoutinator | Published09/13/2023 | SeverityHigh |
CVE-2023-39914BER/CER/DER decoder panics on invalid input | Exploitation statusNot known exploited | FixYes | Affected productbcder | Published09/13/2023 | SeverityHigh |
CVE-2023-0158Triggered crash on direct RRDP access | Exploitation statusNot known exploited | FixNot confirmed | Affected productKrill | Published01/17/2023 | SeverityHigh |
CVE-2022-3204NRDelegation Attack | Exploitation statusNot known exploited | FixNot confirmed | Affected productunbound | Published09/26/2022 | SeverityHigh |
CVE-2022-3029Fatal error on incorrect base64 data in RRDP | Exploitation statusNot confirmed | FixNot confirmed | Affected productRoutinator | Published09/13/2022 | SeverityUnknown |
CVE-2022-30699Novel "ghost domain names" attack by updating almost expired delegation information | Exploitation statusNot confirmed | FixNot confirmed | Affected productunbound | Published08/01/2022 | SeverityUnknown |
CVE-2022-30698Novel "ghost domain names" attack by introducing subdomain delegations | Exploitation statusNot confirmed | FixNot confirmed | Affected productunbound | Published08/01/2022 | SeverityUnknown |
CVE-2021-43174gzip transfer encoding caused out-of-memory crash | Exploitation statusNot confirmed | FixNot confirmed | Affected productRoutinator | Published11/09/2021 | SeverityUnknown |
CVE-2021-43173Hanging RRDP request | Exploitation statusNot confirmed | FixNot confirmed | Affected productRoutinator | Published11/09/2021 | SeverityUnknown |
CVE-2021-43172Infinite length chain of RRDP repositories | Exploitation statusNot confirmed | FixNot confirmed | Affected productRoutinator | Published11/09/2021 | SeverityUnknown |
CVE-2021-41531Invalid RPKI data could disable Route Origin Validation on RTR clients. | Exploitation statusNot confirmed | FixNot confirmed | Affected productRoutinator | Published09/21/2021 | SeverityUnknown |
CVE-2020-28935Local symlink attack in Unbound and NSD | Exploitation statusNot confirmed | FixNot confirmed | Affected productunbound | Published12/07/2020 | SeverityUnknown |
CVE-2017-15105CVE-2017-15105 | Exploitation statusNot confirmed | FixNot confirmed | Affected productunbound | Published01/23/2018 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan