NLnet Labs Unbound是荷兰NLnet Labs组织的域名系统解析服务器。 NLnet Labs Unbound 1.6.0版本至1.25.1版本存在处理逻辑错误漏洞,该漏洞源于对泛域名RRset的重放处理不当,可能导致攻击者通过DNSSEC签名的域名和CNAME包装记录,利用serve expired路径将注入的泛域名RRset缓存为安全状态,从而更改特定记录。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NLnet Labs | Unbound | 1.6.0< 1.25.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NLnet Labs | Unbound | 1.6.0 ~ 1.25.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55973 | 7.5 HIGH | 'dns-error-reporting: yes' leads to stack buffer overflow |
| CVE-2026-44690 | 7.5 HIGH | Cross-zone wildcard cache poisoning via RRSIG.labels manipulation |
| CVE-2026-32665 | 7.5 HIGH | Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass |
| CVE-2026-40691 | 7.5 HIGH | Packet of death for DNSCrypt over TCP |
| CVE-2026-50248 | 6.5 MEDIUM | BOGUS configured primary hostname accepted for XFR in auth/rpz zones |
| CVE-2026-50046 | 5.9 MEDIUM | Possible heap use-after-free in an error path when a DoT forwarded query is jostled out |
| CVE-2026-55717 | 5.9 MEDIUM | 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash |
| CVE-2026-55991 | 5.9 MEDIUM | Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 |
| CVE-2026-44621 | 5.9 MEDIUM | Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abr |
| CVE-2026-52863 | 5.9 MEDIUM | Memory corruption could lead to crash and denial of service |
| CVE-2026-55990 | 5.9 MEDIUM | Packet of death for a DNSCrypt misconfigured Unbound |
| CVE-2026-14586 | 5.9 MEDIUM | Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments |
| CVE-2026-56444 | 5.9 MEDIUM | Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout |
| CVE-2026-50251 | 5.3 MEDIUM | Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush |
| CVE-2026-50045 | 5.3 MEDIUM | 'max-global-quota' reset by DNSSEC validation restarts |
| CVE-2026-56416 | 4.8 MEDIUM | Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name |
| CVE-2026-44687 | 3.7 LOW | Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legi |
| CVE-2026-42955 | 3.7 LOW | Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-tim |
| CVE-2026-54478 | 3.7 LOW | DNS Cookie bypass when combined with proxy-protocol use |
| CVE-2026-41637 | 3.7 LOW | Degradation of resolution service from improperly accounted client-terminated DNS-over-QUI |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet