Nlnetlabs
Nlnetlabs Unbound: vulnerabilidades y CVE
Nlnetlabs Unbound tiene 78 vulnerabilidades publicadas, 46 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE78
Últimos 12 meses46
Críticas9
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85501 | Alta (7.5) | 0.48% | — | 16 sept 2026 | Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic… |
| CVE-2026-82720 | Media (5.9) | 0.38% | — | 16 sept 2026 | NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to… |
| CVE-2026-82717 | Alta (8.4) | 0.78% | — | 16 sept 2026 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The… |
| CVE-2026-81642 | Crítica (9.1) | 0.96% | — | 16 sept 2026 | In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an… |
| CVE-2026-81634 | Alta (7.5) | 0.48% | — | 16 sept 2026 | In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the… |
| CVE-2026-80225 | Alta (7.5) | 0.48% | — | 16 sept 2026 | In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and… |
| CVE-2026-78227 | Media (6.5) | 0.34% | — | 16 sept 2026 | NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS… |
| CVE-2026-77955 | Media (4.4) | 0.17% | — | 16 sept 2026 | In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered… |
| CVE-2026-77860 | Baja (3.7) | 0.30% | — | 16 sept 2026 | In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter… |
| CVE-2026-56444 | Media (5.9) | 0.36% | — | 22 jul 2026 | In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the… |
| CVE-2026-56416 | Media (4.8) | 0.14% | — | 22 jul 2026 | In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as… |
| CVE-2026-55991 | Media (5.9) | 0.36% | — | 22 jul 2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single… |
| CVE-2026-55990 | Media (5.9) | 0.36% | — | 22 jul 2026 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix… |
| CVE-2026-55973 | Alta (7.5) | 0.46% | — | 22 jul 2026 | In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the… |
| CVE-2026-55717 | Media (5.9) | 0.36% | — | 22 jul 2026 | In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override'… |
| CVE-2026-55708 | Baja (3.1) | 0.16% | — | 22 jul 2026 | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is… |
| CVE-2026-54478 | Baja (3.7) | 0.24% | — | 22 jul 2026 | In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address… |
| CVE-2026-52863 | Media (5.9) | 0.36% | — | 22 jul 2026 | In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the… |
| CVE-2026-50252 | Media (5.7) | 0.16% | — | 22 jul 2026 | In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend… |
| CVE-2026-50251 | Media (5.3) | 0.40% | — | 22 jul 2026 | In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can… |
| CVE-2026-50248 | Media (6.5) | 0.17% | — | 22 jul 2026 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that… |
| CVE-2026-50243 | Media (6.3) | 0.13% | — | 22 jul 2026 | In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger,… |
| CVE-2026-50046 | Media (5.9) | 0.36% | — | 22 jul 2026 | In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct… |
| CVE-2026-50045 | Media (5.3) | 0.46% | — | 22 jul 2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured… |
| CVE-2026-46582 | Baja (3.7) | 0.25% | — | 22 jul 2026 | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before… |
| CVE-2026-44690 | Alta (7.5) | 0.14% | — | 22 jul 2026 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that… |
| CVE-2026-44687 | Baja (3.7) | 0.33% | — | 22 jul 2026 | In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN… |
| CVE-2026-44621 | Media (5.9) | 0.36% | — | 22 jul 2026 | With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and… |
| CVE-2026-42955 | Baja (3.7) | 0.27% | — | 22 jul 2026 | In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up… |
| CVE-2026-41637 | Baja (3.7) | 0.37% | — | 22 jul 2026 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.