Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
87 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.14% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under… | |
| Analizada | Baja (3.7) | 0.22% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the parent. This is caused by an off-by-one error in 'harden-below-nxdomain' logic; enabled… | |
| Analizada | Media (5.9) | 0.25% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow… | |
| Analizada | Baja (3.7) | 0.20% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names'… | |
| Analizada | Baja (3.7) | 0.37% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already in-flight resolution queries. This results in degradation of resolution service for new clients for… | |
| Analizada | Alta (7.5) | 0.29% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is… | |
| Analizada | Alta (7.5) | 0.47% | — | Nlnetlabs Unbound | 22/7/2026 | 24/7/2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has… | |
| Pendiente de análisis | Media (5.9) | 0.26% | — | Libngtcp2AINlnetlabs UnboundAI | 22/7/2026 | 22/7/2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in… | |
| Aplazada | Media (5.3) | 0.30% | — | UnboundAI | 25/6/2026 | 25/6/2026 | An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation. | |
| Analizada | Media (5.8) | 0.12% | — | Spearman Unbounded-spsc | 12/6/2026 | 17/6/2026 | unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race. At time of publication, there are no publicly available patches. | |
| Aplazada | Media (4.3) | 0.23% | — | Mercusys Ac12gAINlnetlabs UnboundAI | 3/6/2026 | 22/7/2026 | Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 responds to version.bind CHAOS TXT queries, disclosing the DNS resolver software version (unbound 1.22.0), aiding targeted attacks against known vulnerabilities. | |
| Aplazada | Alta (7.5) | 0.30% | — | Unboundstudio Accordion FAQAI | 2/6/2026 | 22/7/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in UnboundStudio Accordion FAQ allows PHP Local File Inclusion. This issue affects Accordion FAQ: from n/a through 2.2.1. | |
| Aplazada | Alta (7.1) | 0.15% | — | Unboundstudio Accordion FAQAI | 2/6/2026 | 22/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in UnboundStudio Accordion FAQ allows Reflected XSS. This issue affects Accordion FAQ: from n/a through 2.2.1. | |
| Analizada | Media (4.6) | 0.28% | — | Nlnetlabs Unbound | 20/5/2026 | 24/7/2026 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the… | |
| Modificada | Media (6.9) | 0.72% | — | Nlnetlabs Unbound | 20/5/2026 | 1/9/2026 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable… | |
| Analizada | Media (5.7) | 0.27% | — | Nlnetlabs Unbound | 20/5/2026 | 24/7/2026 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply… | |
| Modificada | Alta (8.7) | 0.72% | — | Nlnetlabs Unbound | 20/5/2026 | 1/9/2026 | NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section… | |
| Modificada | Alta (8.7) | 0.78% | — | Nlnetlabs Unbound | 20/5/2026 | 26/8/2026 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the… | |
| Analizada | Media (6.9) | 0.40% | — | Nlnetlabs Unbound | 20/5/2026 | 24/7/2026 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the attack. An adversary… | |
| Modificada | Media (6.9) | 0.72% | — | Nlnetlabs Unbound | 20/5/2026 | 1/9/2026 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for… | |
| Modificada | Media (6.6) | 0.83% | — | Nlnetlabs Unbound | 20/5/2026 | 26/8/2026 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the… | |
| Analizada | Media (6.6) | 0.14% | — | Nlnetlabs Unbound | 20/5/2026 | 24/7/2026 | NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to… | |
| Modificada | Crítica (9.1) | 1.1% | — | Nlnetlabs Unbound | 20/5/2026 | 25/8/2026 | NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by… | |
| Analizada | Media (4.6) | 0.40% | — | Nlnetlabs Unbound | 20/5/2026 | 24/7/2026 | NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the vulnerability… | |
| Aplazada | Media (5.7) | 0.33% | — | Nlnetlabs UnboundAI | 22/10/2025 | 17/6/2026 | NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the… |