Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Authoritative HIGH 8.6
CVE-2026-42000

Insufficient Validation of Names During AXFR

Fix: 4.9.15 / 5.0.5+
Fix from $1,950 2026-05-21
Authoritative HIGH 7.5
CVE-2026-42001

Insufficient Validation of Autoprimary SOA Queries

Fix: 4.9.15 / 5.0.5+
Fix from $1,950 2026-05-21
Authoritative HIGH 7.5
CVE-2026-42002

Concurrency and locking defects in GSS-TSIG

Fix: 4.9.15 / 5.0.5+
Fix from $1,950 2026-05-21
Authoritative MEDIUM 6.5
CVE-2026-42396

Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail

Fix: 4.9.15 / 5.0.5+
Fix from $1,600 2026-05-21
Authoritative CRITICAL 9.8
CVE-2026-33608

An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its confi…

Fix: 4.9.14 / 5.0.4+
Fix from $2,300 2026-04-22
Dnsdist CRITICAL 9.1
CVE-2026-33598

A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet c…

Fix: 1.9.13 / 2.0.4+
Fix from $2,300 2026-04-22
Dnsdist HIGH 8.2
CVE-2026-33602

A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Dnsdist HIGH 8.1
CVE-2026-33599

A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) opti…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Dnsdist HIGH 7.5
CVE-2026-33597

PRSD detection denial of service

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Authoritative HIGH 7.5
CVE-2026-33610

A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS updat…

Fix: 4.9.14 / 5.0.4+
Fix from $1,950 2026-04-22
Dnsdist MEDIUM 6.5
CVE-2026-33596

A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly…

Fix: 1.9.13 / 2.0.4+
Fix from $1,600 2026-04-22
Authoritative MEDIUM 6.5
CVE-2026-33609

Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees.

Fix: 4.9.14 / 5.0.4+
Fix from $1,600 2026-04-22
Dnsdist HIGH 7.5
CVE-2026-33254

An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial o…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Dnsdist HIGH 7.5
CVE-2026-33593

A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Dnsdist HIGH 7.5
CVE-2026-33594

A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accu…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Dnsdist HIGH 7.5
CVE-2026-33595

A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources wer…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Recursor HIGH 7.5
CVE-2026-33256

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…

Fix: 5.2.9 / 5.3.6+
Fix from $1,950 2026-04-22
Authoritative HIGH 7.5
CVE-2026-33257

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Recursor HIGH 7.5
CVE-2026-33258

By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches.

Fix: 5.2.9 / 5.3.6+
Fix from $1,950 2026-04-22
Authoritative HIGH 7.5
CVE-2026-33260

An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w…

Fix: 1.9.13 / 2.0.4+
Fix from $1,950 2026-04-22
Recursor MEDIUM 5.9
CVE-2026-33261

A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service.

Fix: 5.2.9 / 5.3.6+
Fix from $1,600 2026-04-22
Recursor MEDIUM 5.9
CVE-2026-33262

An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Coo…

Fix: 5.2.9 / 5.3.6+
Fix from $1,600 2026-04-22
Recursor MEDIUM 5.0
CVE-2026-33259

Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurren…

Fix: 5.2.9 / 5.3.6+
Fix from $1,600 2026-04-22
Dnsdist HIGH 7.5
CVE-2026-27854

An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in cust…

Fix: 1.9.12 / 2.0.3+
Fix from $1,950 2026-03-31
Dnsdist HIGH 8.2
CVE-2026-24028

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to…

Fix: 1.9.12 / 2.0.3+
Fix from $1,950 2026-03-31
Dnsdist HIGH 7.5
CVE-2026-24030

An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a…

Fix: 1.9.12 / 2.0.3+
Fix from $1,950 2026-03-31
Dnsdist HIGH 7.5
CVE-2026-27853

An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResp…

Fix: 1.9.12 / 2.0.3+
Fix from $1,950 2026-03-31
Dnsdist MEDIUM 6.5
CVE-2026-24029

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the AC…

Fix: 1.9.12 / 2.0.3+
Fix from $1,600 2026-03-31
Recursor MEDIUM 5.3
CVE-2026-0398

Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.

Fix: 5.1.10 / 5.2.8+
Fix from $1,600 2026-02-09
Recursor MEDIUM 5.3
CVE-2026-24027

Crafted zones can lead to increased incoming network traffic.

Fix: 5.1.10 / 5.2.8+
Fix from $1,600 2026-02-09