Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

NLnet Labs — Vulnerabilities & Security Advisories 77

Browse all 77 CVE security advisories affecting NLnet Labs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

NLnet Labs operates as a non-profit research organization primarily focused on developing open-source software for the Domain Name System (DNS) and internet infrastructure. Its most prominent contribution is Unbound, a validating, recursive, and caching DNS resolver widely deployed for its emphasis on security and privacy. Historically, vulnerabilities associated with its software have predominantly involved memory corruption issues, such as buffer overflows and use-after-free errors, rather than application-layer flaws like cross-site scripting. These defects typically stem from low-level C code implementation details. While no catastrophic, widespread breaches have defined its public history, the presence of twenty recorded CVEs indicates ongoing challenges in maintaining strict memory safety within complex network protocols. The organization generally addresses these findings through prompt patches, reflecting a standard open-source maintenance lifecycle where technical rigor in cryptographic and network logic is prioritized over commercial feature expansion.

Found 53 results / 77 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-40691 Packet of death for DNSCrypt over TCP — Unbound CWE-122 7.5 High 2026-07-22
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass — Unbound CWE-1284 7.5 High 2026-07-22
CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments — Unbound CWE-617 5.9 Medium 2026-07-22
CVE-2026-44608 Use after free and crash under special conditions in RPZ code — Unbound CWE-413 - - 2026-05-20
CVE-2026-44390 Unbounded name compression in certain cases causes degradation of service — Unbound CWE-407 6.9 Medium 2026-05-20
CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section — Unbound CWE-349 - - 2026-05-20
CVE-2026-42959 Crash during DNSSEC validation of malicious content — Unbound CWE-824 8.7 High 2026-05-20
CVE-2026-42944 Heap overflow with multiple NSID, COOKIE, PADDING EDNS options — Unbound CWE-197 8.7 High 2026-05-20
CVE-2026-42923 Degradation of service with unbounded NSEC3 hash calculations — Unbound CWE-407 - - 2026-05-20
CVE-2026-42534 Jostle logic bypass degrades resolution performance — Unbound CWE-440 6.9 Medium 2026-05-20
CVE-2026-41292 Long list of incoming EDNS options degrades performance — Unbound CWE-407 6.6 Medium 2026-05-20
CVE-2026-40622 Another 'ghost domain names' attack variant — Unbound - - 2026-05-20
CVE-2026-33278 Possible arbitrary code execution during DNSSEC validation — Unbound CWE-416 9.1 Critical 2026-05-20
CVE-2026-32792 Packet of death with DNSCrypt — Unbound CWE-166 - - 2026-05-20
CVE-2025-11411 Possible domain hijacking via promiscuous records in the authority section — Unbound CWE-349 7.5AI High AI 2025-10-22
CVE-2025-5994 Cache poisoning via the ECS-enabled Rebirthday Attack — Unbound CWE-349 5.3 - 2025-07-16
CVE-2024-8508 Unbounded name compression could lead to Denial of Service — Unbound CWE-606 5.3 Medium 2024-10-03
CVE-2024-1931 Denial of service when trimming EDE text on positive replies — Unbound CWE-835 7.5 High 2024-03-07
CVE-2022-3204 NRDelegation Attack — Unbound 7.5 - 2022-09-26
CVE-2022-30699 Novel "ghost domain names" attack by updating almost expired delegation information — Unbound 6.5 - 2022-08-01
CVE-2022-30698 Novel "ghost domain names" attack by introducing subdomain delegations — Unbound 6.5 - 2022-08-01
CVE-2020-28935 Local symlink attack in Unbound and NSD — Unbound CWE-59 7.8 - 2020-12-07
CVE-2017-15105 Unbound 安全漏洞 — unbound CWE-358 5.3 - 2018-01-23

This page lists every published CVE security advisory associated with NLnet Labs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.