NLnet Labs Unbound是NLnet Labs开源的一个高性能DNS解析器。 NLnet Labs Unbound 1.25.0及之前版本存在安全漏洞,该漏洞源于DNSSEC验证器中查询DS记录负缓存时未考虑NSEC3哈希计算限制,可能导致服务降级,攻击者通过签名高迭代次数的NSEC3记录并查询可消耗哈希计算资源,同时持有全局锁阻塞其他线程。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NLnet Labs | Unbound | < 1.25.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NLnet Labs | Unbound | 0 ~ 1.25.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-33278 | 9.1 CRITICAL | Possible arbitrary code execution during DNSSEC validation |
| CVE-2026-42534 | 6.9 MEDIUM | Jostle logic bypass degrades resolution performance |
| CVE-2026-44390 | 6.9 MEDIUM | Unbounded name compression in certain cases causes degradation of service |
| CVE-2026-41292 | 6.6 MEDIUM | Long list of incoming EDNS options degrades performance |
| CVE-2026-42959 | Crash during DNSSEC validation of malicious content | |
| CVE-2026-42944 | Heap overflow with multiple NSID, COOKIE, PADDING EDNS options | |
| CVE-2026-42960 | Possible cache poisoning via promiscuous records for the authority section | |
| CVE-2026-32792 | Packet of death with DNSCrypt | |
| CVE-2026-40622 | Another 'ghost domain names' attack variant | |
| CVE-2026-44608 | Use after free and crash under special conditions in RPZ code |
No comments yet