Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

NLnet Labs — Vulnerabilities & Security Advisories 77

Browse all 77 CVE security advisories affecting NLnet Labs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NLnet Labs operates as a non-profit research organization primarily focused on developing open-source software for the Domain Name System (DNS) and internet infrastructure. Its most prominent contribution is Unbound, a validating, recursive, and caching DNS resolver widely deployed for its emphasis on security and privacy. Historically, vulnerabilities associated with its software have predominantly involved memory corruption issues, such as buffer overflows and use-after-free errors, rather than application-layer flaws like cross-site scripting. These defects typically stem from low-level C code implementation details. While no catastrophic, widespread breaches have defined its public history, the presence of twenty recorded CVEs indicates ongoing challenges in maintaining strict memory safety within complex network protocols. The organization generally addresses these findings through prompt patches, reflecting a standard open-source maintenance lifecycle where technical rigor in cryptographic and network logic is prioritized over commercial feature expansion.

CVE ID Title CVSS Severity Published
CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN — Unbound CWE-193 3.7 Low 2026-07-22
CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated — Unbound CWE-754 5.9 Medium 2026-07-22
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records — Unbound CWE-672 3.7 Low 2026-07-22
CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries — Unbound CWE-772 3.7 Low 2026-07-22
CVE-2026-40691 Packet of death for DNSCrypt over TCP — Unbound CWE-122 7.5 High 2026-07-22
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass — Unbound CWE-1284 7.5 High 2026-07-22
CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments — Unbound CWE-617 5.9 Medium 2026-07-22
CVE-2026-12490 Bypass of client certificate verification with transfer over TLS — NSD CWE-306 - - 2026-06-25
CVE-2026-12246 Out of bounds stack write with crafted APL RR — NSD CWE-120 - - 2026-06-25
CVE-2026-12245 Denial of DNS over TLS service by any DoT client — NSD CWE-416 - - 2026-06-25
CVE-2026-12244 Heap overflow and crash with crafted SVCB RR — NSD CWE-190 - - 2026-06-25
CVE-2026-10846 Insufficient verification that responses belong to a query — ldns CWE-346 - - 2026-06-10
CVE-2026-49235 Routinator crashes on specifically crafted RRDP XML files — Routinator CWE-755 - - 2026-06-08
CVE-2026-49234 Routinator crashes on specifically crafted ASN strings in the API — Routinator CWE-20 - - 2026-06-08
CVE-2026-49233 Routinator cache path traversal using rogue rsync URIs — Routinator CWE-22 - - 2026-06-08
CVE-2026-49232 Routinator exits when accepting an incoming HTTP or RTR connection fails — Routinator CWE-755 - - 2026-06-08
CVE-2026-44608 Use after free and crash under special conditions in RPZ code — Unbound CWE-413 - - 2026-05-20
CVE-2026-44390 Unbounded name compression in certain cases causes degradation of service — Unbound CWE-407 6.9 Medium 2026-05-20
CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section — Unbound CWE-349 - - 2026-05-20
CVE-2026-42959 Crash during DNSSEC validation of malicious content — Unbound CWE-824 8.7 High 2026-05-20
CVE-2026-42944 Heap overflow with multiple NSID, COOKIE, PADDING EDNS options — Unbound CWE-197 8.7 High 2026-05-20
CVE-2026-42923 Degradation of service with unbounded NSEC3 hash calculations — Unbound CWE-407 - - 2026-05-20
CVE-2026-42534 Jostle logic bypass degrades resolution performance — Unbound CWE-440 6.9 Medium 2026-05-20
CVE-2026-41292 Long list of incoming EDNS options degrades performance — Unbound CWE-407 6.6 Medium 2026-05-20
CVE-2026-40622 Another 'ghost domain names' attack variant — Unbound - - 2026-05-20
CVE-2026-33278 Possible arbitrary code execution during DNSSEC validation — Unbound CWE-416 9.1 Critical 2026-05-20
CVE-2026-32792 Packet of death with DNSCrypt — Unbound CWE-166 - - 2026-05-20
CVE-2025-11411 Possible domain hijacking via promiscuous records in the authority section — Unbound CWE-349 7.5AI High AI 2025-10-22
CVE-2025-5994 Cache poisoning via the ECS-enabled Rebirthday Attack — Unbound CWE-349 5.3 - 2025-07-16
CVE-2025-0638 Routinator crashes when illegal characters are present in manifest file names — Routinator CWE-1286 7.5 High 2025-01-22

This page lists every published CVE security advisory associated with NLnet Labs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.