LIVE · cybersecurity feed
Live wire
vendor

Nlnetlabs

19 CVEs published in the last four months. Exploited flaws first.

Critical3
High16
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-4296010criticalunboundNLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the a108d ago
CVE-2026-332789.8criticalunboundNLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enab108d ago
CVE-2026-502529.3criticalunboundIn NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a 45d ago
CVE-2026-122448.8highnsdIf NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS72d ago
CVE-2026-122468.1highnsdNSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for 72d ago
CVE-2026-492337.5highroutinatorRoutinator does not properly check the module component of rsync URIs, which are used to create the file system pa89d ago
CVE-2026-492347.5highroutinatorWhen sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint89d ago
CVE-2026-492357.5highroutinatorWhen Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crash89d ago
CVE-2026-108467.5highldnsNLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, l87d ago
CVE-2026-122457.5highnsdNSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the72d ago
CVE-2026-124907.5highnsdWhen a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certif72d ago
CVE-2026-326657.5highunboundIn NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first45d ago
CVE-2026-406917.5highunboundIn Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts45d ago
CVE-2026-446907.5highunboundIn NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined45d ago
CVE-2026-559737.5highunboundIn NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-C45d ago
CVE-2026-406227.5highunboundNLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' famil108d ago
CVE-2026-412927.5highunboundNLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to 108d ago
CVE-2026-429447.5highunboundNLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow whe108d ago
CVE-2026-429597.5highunboundNLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validato108d ago

Filter the full tracker by Nlnetlabs