Vulnerability index

Browse CVEs

77 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2026-42000 Insufficient Validation of Names During AXFR Authoritative 4.9.15 / 5.0.5+ Fix from $1,9502026-05-21 HIGH 7.5 CVE-2026-42001 Insufficient Validation of Autoprimary SOA Queries Authoritative 4.9.15 / 5.0.5+ Fix from $1,9502026-05-21 HIGH 7.5 CVE-2026-42002 Concurrency and locking defects in GSS-TSIG Authoritative 4.9.15 / 5.0.5+ Fix from $1,9502026-05-21 MEDIUM 6.5 CVE-2026-42396 Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail Authoritative 4.9.15 / 5.0.5+ Fix from $1,6002026-05-21 CRITICAL 9.8 CVE-2026-33608 An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its confi… Authoritative 4.9.14 / 5.0.4+ Fix from $2,3002026-04-22 CRITICAL 9.1 CVE-2026-33598 A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet c… Dnsdist 1.9.13 / 2.0.4+ Fix from $2,3002026-04-22 HIGH 8.2 CVE-2026-33602 A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write… Dnsdist 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 HIGH 8.1 CVE-2026-33599 A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) opti… Dnsdist 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-33597 PRSD detection denial of service Dnsdist 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-33610 A rogue primary server may cause file descriptor exhaustion and eventually a denial of service, when a PowerDNS secondary server forwards a DNS updat… Authoritative 4.9.14 / 5.0.4+ Fix from $1,9502026-04-22 MEDIUM 6.5 CVE-2026-33596 A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly… Dnsdist 1.9.13 / 2.0.4+ Fix from $1,6002026-04-22 MEDIUM 6.5 CVE-2026-33609 Incomplete escaping of LDAP queries when running with 8bit-dns enabled allows users to perform queries of internal domain subtrees. Authoritative 4.9.14 / 5.0.4+ Fix from $1,6002026-04-22 HIGH 7.5 CVE-2026-33254 An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial o… Dnsdist 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-33593 A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query. Dnsdist 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-33594 A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accu… Dnsdist 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-33595 A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources wer… Dnsdist 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-33256 An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w… Recursor 5.2.9 / 5.3.6+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-33257 An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w… Authoritative 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-33258 By publishing and querying a crafted zone an attacker can cause allocation of large entries in the negative and aggressive NSEC(3) caches. Recursor 5.2.9 / 5.3.6+ Fix from $1,9502026-04-22 HIGH 7.5 CVE-2026-33260 An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal w… Authoritative 1.9.13 / 2.0.4+ Fix from $1,9502026-04-22 MEDIUM 5.9 CVE-2026-33261 A zone transition from NSEC to NSEC3 might trigger an internal inconsistency and cause a denial of service. Recursor 5.2.9 / 5.3.6+ Fix from $1,6002026-04-22 MEDIUM 5.9 CVE-2026-33262 An attacker can send replies that result in a null pointer dereference, caused by a missing consistency check and leading to a denial of service. Coo… Recursor 5.2.9 / 5.3.6+ Fix from $1,6002026-04-22 MEDIUM 5.0 CVE-2026-33259 Having many concurrent transfers of the same RPZ can lead to inconsistent RPZ data, use after free and/or a crash of the recursor. Normally concurren… Recursor 5.2.9 / 5.3.6+ Fix from $1,6002026-04-22 HIGH 7.5 CVE-2026-27854 An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in cust… Dnsdist 1.9.12 / 2.0.3+ Fix from $1,9502026-03-31 HIGH 8.2 CVE-2026-24028 An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to… Dnsdist 1.9.12 / 2.0.3+ Fix from $1,9502026-03-31 HIGH 7.5 CVE-2026-24030 An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a… Dnsdist 1.9.12 / 2.0.3+ Fix from $1,9502026-03-31 HIGH 7.5 CVE-2026-27853 An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResp… Dnsdist 1.9.12 / 2.0.3+ Fix from $1,9502026-03-31 MEDIUM 6.5 CVE-2026-24029 When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the AC… Dnsdist 1.9.12 / 2.0.3+ Fix from $1,6002026-03-31 MEDIUM 5.3 CVE-2026-0398 Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor. Recursor 5.1.10 / 5.2.8+ Fix from $1,6002026-02-09 MEDIUM 5.3 CVE-2026-24027 Crafted zones can lead to increased incoming network traffic. Recursor 5.1.10 / 5.2.8+ Fix from $1,6002026-02-09