Vulnerability index

Browse CVEs

56 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unbound MEDIUM 5.9
CVE-2026-56444

In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > dis…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound HIGH 7.5
CVE-2026-55973

In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the la…

Fix: 1.25.2+
Fix from $1,950 2026-07-22
Unbound MEDIUM 5.9
CVE-2026-55717

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound MEDIUM 5.9
CVE-2026-55990

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matchin…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound MEDIUM 5.9
CVE-2026-55991

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertio…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound CRITICAL 9.3
CVE-2026-50252

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the ent…

Fix: 1.25.2+
Fix from $2,300 2026-07-22
Unbound MEDIUM 6.5
CVE-2026-50248

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is …

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound MEDIUM 5.9
CVE-2026-50046

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('se…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound MEDIUM 5.9
CVE-2026-52863

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of t…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound MEDIUM 5.3
CVE-2026-50251

In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue recor…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound HIGH 7.5
CVE-2026-44690

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during…

Fix: 1.25.2+
Fix from $1,950 2026-07-22
Unbound MEDIUM 5.3
CVE-2026-50045

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unboun…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Unbound HIGH 7.5
CVE-2026-32665

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new…

Fix: 1.25.2+
Fix from $1,950 2026-07-22
Unbound HIGH 7.5
CVE-2026-40691

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound …

Fix: 1.25.2+
Fix from $1,950 2026-07-22
Unbound MEDIUM 5.9
CVE-2026-44621

With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could event…

Fix: 1.25.2+
Fix from $1,600 2026-07-22
Nsd HIGH 8.1
CVE-2026-12246

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite t…

Fix: 4.14.3+
Fix from $1,950 2026-06-25
Nsd HIGH 7.5
CVE-2026-12245

NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be trigg…

Fix: 4.14.3+
Fix from $1,950 2026-06-25
Nsd HIGH 7.5
CVE-2026-12490

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no c…

Fix: 4.14.3+
Fix from $1,950 2026-06-25
Nsd HIGH 8.8
CVE-2026-12244

If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVC…

Fix: 4.14.3+
Fix from $1,950 2026-06-25
Ldns HIGH 7.5
CVE-2026-10846

NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination…

Fix: 1.9.1+
Fix from $1,950 2026-06-10
Routinator HIGH 7.5
CVE-2026-49234

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only a…

Fix: 0.15.2+
Fix from $1,950 2026-06-08
Routinator HIGH 7.5
CVE-2026-49235

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes.

Fix: 0.15.2+
Fix from $1,950 2026-06-08
Routinator HIGH 7.5
CVE-2026-49233

Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This …

Fix: 0.15.2+
Fix from $1,950 2026-06-08
Unbound CRITICAL 10.0
CVE-2026-42960

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSet…

Fix: 1.25.1+
Fix from $2,300 2026-05-20
Unbound MEDIUM 5.9
CVE-2026-44608

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-th…

Fix: 1.25.1+
Fix from $1,600 2026-05-20
Unbound MEDIUM 5.3
CVE-2026-44390

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform …

Fix: 1.25.1+
Fix from $1,600 2026-05-20
Unbound HIGH 7.5
CVE-2026-41292

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS…

Fix: 1.25.1+
Fix from $1,950 2026-05-20
Unbound HIGH 7.5
CVE-2026-42944

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS…

Fix: 1.25.1+
Fix from $1,950 2026-05-20
Unbound HIGH 7.5
CVE-2026-42959

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given ma…

Fix: 1.25.1+
Fix from $1,950 2026-05-20
Unbound MEDIUM 5.3
CVE-2026-42534

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution pe…

Fix: 1.25.1+
Fix from $1,600 2026-05-20