NSD
NLnet Labs- Software type
- —
- Catalog vulnerabilities
- 9
Severity across 9 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 9 analyzed records
A short verification protects source data and prevents automated AI requests.
As of 09/11/2026, within CyStack's analyzed data, NSD has 8 security vulnerabilities published in the last 90 days. Of these, 7 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of NSD and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| CVE | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-19538Bypass of BLOCKED ACL items on proxy protocol port over TCP or TLS | Exploitation statusNot known exploited | FixYes | Published08/26/2026 | SeverityHigh |
CVE-2026-19401Remote UDP DoS by sending multiple DNS Cookie options | Exploitation statusNot known exploited | FixYes | Published08/26/2026 | SeverityHigh |
CVE-2026-18916Remote TCP DoS by throttling the TCP receive window | Exploitation statusNot known exploited | FixYes | Published08/26/2026 | SeverityMedium |
CVE-2026-18664Wrong interpretation of ACL ranges | Exploitation statusNot known exploited | FixYes | Published08/26/2026 | SeverityHigh |
CVE-2026-12490Bypass of client certificate verification with transfer over TLS | Exploitation statusNot known exploited | FixYes | Published06/25/2026 | SeverityHigh |
CVE-2026-12246Out of bounds stack write with crafted APL RR | Exploitation statusNot known exploited | FixYes | Published06/25/2026 | SeverityHigh |
CVE-2026-12245Denial of DNS over TLS service by any DoT client | Exploitation statusNot known exploited | FixYes | Published06/25/2026 | SeverityHigh |
CVE-2026-12244Heap overflow and crash with crafted SVCB RR | Exploitation statusNot known exploited | FixYes | Published06/25/2026 | SeverityHigh |
CVE-2020-28935Local symlink attack in Unbound and NSD | Exploitation statusNot confirmed | FixNot confirmed | Published12/07/2020 | SeverityUnknown |