Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
115 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.13% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of the upstream answer and can instead… | |
| Analizada | Media (5.9) | 0.36% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still… | |
| Analizada | Media (5.3) | 0.46% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream… | |
| Analizada | Baja (3.7) | 0.19% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure… | |
| Analizada | Alta (7.5) | 0.14% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under… | |
| Analizada | Baja (3.7) | 0.22% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the parent. This is caused by an off-by-one error in 'harden-below-nxdomain' logic; enabled… | |
| Analizada | Media (5.9) | 0.25% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow… | |
| Analizada | Baja (3.7) | 0.20% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names'… | |
| Analizada | Baja (3.7) | 0.37% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already in-flight resolution queries. This results in degradation of resolution service for new clients for… | |
| Analizada | Alta (7.5) | 0.29% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is… | |
| Analizada | Alta (7.5) | 0.47% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has… | |
| Pendiente de análisis | Media (5.9) | 0.26% | — | Libngtcp2AINlnetlabs UnboundAI | 22/7/2026 | 22/7/2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in… | |
| Analizada | Alta (8.2) | 0.22% | — | Nlnetlabs NSD | 25/6/2026 | 26/6/2026 | When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the… | |
| Analizada | Alta (7.2) | 0.44% | — | Nlnetlabs NSD | 25/6/2026 | 26/6/2026 | NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes. | |
| Analizada | Alta (8.7) | 0.46% | — | Nlnetlabs NSD | 25/6/2026 | 26/6/2026 | NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response. | |
| Analizada | Alta (8.7) | 0.49% | — | Nlnetlabs NSD | 25/6/2026 | 26/6/2026 | If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap… | |
| Analizada | Alta (8.2) | 0.15% | — | Nlnetlabs Ldns | 10/6/2026 | 23/7/2026 | NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This… | |
| Analizada | Alta (8.7) | 0.46% | — | Nlnetlabs Routinator | 8/6/2026 | 23/7/2026 | When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. | |
| Analizada | Alta (8.2) | 0.33% | — | Nlnetlabs Routinator | 8/6/2026 | 23/7/2026 | When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access from untrusted networks. | |
| Analizada | Alta (8.3) | 0.50% | — | Nlnetlabs Routinator | 8/6/2026 | 23/7/2026 | Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This allows for path traversal by having a module name containing .., potentially providing an attacker access to the entire Routinator rsync cache. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Nlnetlabs RoutinatorAI | 8/6/2026 | 23/7/2026 | Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as running out of file descriptors. This condition can be triggered maliciously by an attacker by opening a large number of connections to the HTTP or RTR server. This only affects users that make… | |
| Aplazada | Media (4.3) | 0.23% | — | Mercusys Ac12gAINlnetlabs UnboundAI | 3/6/2026 | 22/7/2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (unbound 1.22.0), aiding targeted attacks against known vulnerabilities. | |
| Analizada | Media (4.6) | 0.28% | — | Nlnetlabs Unbound | 20/5/2026 | 24/7/2026 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the… | |
| Modificada | Media (6.9) | 0.72% | — | Nlnetlabs Unbound | 20/5/2026 | 1/9/2026 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable… | |
| Analizada | Media (5.7) | 0.27% | — | Nlnetlabs Unbound | 20/5/2026 | 24/7/2026 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply… |