CVE-2026-56444
- EPSS 0.24%
- Veröffentlicht 22.07.2026 13:10:34
- Zuletzt bearbeitet 24.07.2026 13:43:15
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve exp...
CVE-2026-56416
- EPSS 0.14%
- Veröffentlicht 22.07.2026 13:10:24
- Zuletzt bearbeitet 24.07.2026 14:25:29
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ....
CVE-2026-55991
- EPSS 0.24%
- Veröffentlicht 22.07.2026 13:10:13
- Zuletzt bearbeitet 24.07.2026 14:25:18
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one...
CVE-2026-55990
- EPSS 0.26%
- Veröffentlicht 22.07.2026 13:10:01
- Zuletzt bearbeitet 24.07.2026 14:24:26
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at th...
CVE-2026-55973
- EPSS 0.46%
- Veröffentlicht 22.07.2026 13:09:50
- Zuletzt bearbeitet 24.07.2026 14:24:21
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a d...
CVE-2026-55717
- EPSS 0.24%
- Veröffentlicht 22.07.2026 13:09:40
- Zuletzt bearbeitet 24.07.2026 14:24:16
In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who c...
CVE-2026-55708
- EPSS 0.15%
- Veröffentlicht 22.07.2026 13:09:30
- Zuletzt bearbeitet 24.07.2026 14:24:10
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to b...
CVE-2026-54478
- EPSS 0.18%
- Veröffentlicht 22.07.2026 13:09:18
- Zuletzt bearbeitet 24.07.2026 14:24:03
In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared...
CVE-2026-52863
- EPSS 0.24%
- Veröffentlicht 22.07.2026 13:09:06
- Zuletzt bearbeitet 24.07.2026 14:23:56
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is...
CVE-2026-50252
- EPSS 0.12%
- Veröffentlicht 22.07.2026 13:08:54
- Zuletzt bearbeitet 24.07.2026 14:05:44
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their...