NLnet Labs Unbound是荷兰NLnet Labs组织的域名系统解析服务器。 NLnet Labs Unbound 1.23.0版本至1.25.1版本存在输入验证错误漏洞,该漏洞源于当启用‘dns-error-reporting: yes’时,程序读取上游响应的EDNS Report-Channel选项(代码18)并用其长度作为代理域长度,在对代理域执行域名检查时未使用返回长度,导致若代理域后存在垃圾数据,这些字节被移至‘_er.’报告查询名称尾部,后续在‘find_closest_of_ty
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NLnet Labs | Unbound | 1.23.0< 1.25.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NLnet Labs | Unbound | 1.23.0 ~ 1.25.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-32665 | 7.5 HIGH | Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass |
| CVE-2026-40691 | 7.5 HIGH | Packet of death for DNSCrypt over TCP |
| CVE-2026-44690 | 7.5 HIGH | Cross-zone wildcard cache poisoning via RRSIG.labels manipulation |
| CVE-2026-50248 | 6.5 MEDIUM | BOGUS configured primary hostname accepted for XFR in auth/rpz zones |
| CVE-2026-55717 | 5.9 MEDIUM | 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash |
| CVE-2026-55991 | 5.9 MEDIUM | Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 |
| CVE-2026-55990 | 5.9 MEDIUM | Packet of death for a DNSCrypt misconfigured Unbound |
| CVE-2026-56444 | 5.9 MEDIUM | Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout |
| CVE-2026-14586 | 5.9 MEDIUM | Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments |
| CVE-2026-44621 | 5.9 MEDIUM | Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abr |
| CVE-2026-50046 | 5.9 MEDIUM | Possible heap use-after-free in an error path when a DoT forwarded query is jostled out |
| CVE-2026-52863 | 5.9 MEDIUM | Memory corruption could lead to crash and denial of service |
| CVE-2026-50045 | 5.3 MEDIUM | 'max-global-quota' reset by DNSSEC validation restarts |
| CVE-2026-50251 | 5.3 MEDIUM | Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush |
| CVE-2026-56416 | 4.8 MEDIUM | Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name |
| CVE-2026-46582 | 3.7 LOW | A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply |
| CVE-2026-44687 | 3.7 LOW | Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legi |
| CVE-2026-54478 | 3.7 LOW | DNS Cookie bypass when combined with proxy-protocol use |
| CVE-2026-42955 | 3.7 LOW | Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-tim |
| CVE-2026-41637 | 3.7 LOW | Degradation of resolution service from improperly accounted client-terminated DNS-over-QUI |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet