CVE-2026-85501
- EPSS 0.31%
- Veröffentlicht 16.09.2026 08:32:25
- Zuletzt bearbeitet 23.09.2026 19:10:46
Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Lab...
CVE-2026-82720
- EPSS 0.29%
- Veröffentlicht 16.09.2026 08:32:10
- Zuletzt bearbeitet 23.09.2026 19:49:08
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH st...
CVE-2026-82717
- EPSS 0.4%
- Veröffentlicht 16.09.2026 08:31:59
- Zuletzt bearbeitet 23.09.2026 19:50:17
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synth...
CVE-2026-81642
- EPSS 0.52%
- Veröffentlicht 16.09.2026 08:30:58
- Zuletzt bearbeitet 22.09.2026 18:59:21
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its ...
CVE-2026-81634
- EPSS 0.36%
- Veröffentlicht 16.09.2026 08:30:15
- Zuletzt bearbeitet 23.09.2026 19:51:14
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer le...
CVE-2026-80225
- EPSS 0.31%
- Veröffentlicht 16.09.2026 08:30:04
- Zuletzt bearbeitet 23.09.2026 19:57:08
In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncache...
CVE-2026-78227
- EPSS 0.27%
- Veröffentlicht 16.09.2026 08:29:52
- Zuletzt bearbeitet 23.09.2026 20:09:01
NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retransmission buffe...
CVE-2026-77955
- EPSS 0.13%
- Veröffentlicht 16.09.2026 08:29:39
- Zuletzt bearbeitet 23.09.2026 20:19:28
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or ...
CVE-2026-77860
- EPSS 0.27%
- Veröffentlicht 16.09.2026 08:29:23
- Zuletzt bearbeitet 23.09.2026 20:21:00
In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was introduced for ...
CVE-2026-56444
- EPSS 0.24%
- Veröffentlicht 22.07.2026 13:10:34
- Zuletzt bearbeitet 24.07.2026 13:43:15
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve exp...