PatchSiren cyber security CVE debrief
CVE-2026-10846 NLnet Labs CVE debrief
CVE-2026-10846 is a HIGH-severity vulnerability in NLnet Labs ldns, a DNS library used for DNS resolution. Versions 1.2.0 through 1.9.0 are affected when used as a (stub) resolver over UDP. The vulnerability allows for off-path poisoning attacks due to a lack of matching between query and response source addresses, ports, query IDs, and questions.
- Vendor
- NLnet Labs
- Product
- ldns
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-10
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-10
- Advisory updated
- 2026-06-17
Who should care
Developers and administrators using NLnet Labs ldns for DNS resolution in their applications, especially those using it as a (stub) resolver over UDP, should be aware of this vulnerability and take steps to mitigate it.
Technical summary
The vulnerability exists in NLnet Labs ldns versions 1.2.0 through 1.9.0. When used as a (stub) resolver over UDP, ldns does not properly match the query destination address and port with the response source address and port. Additionally, it does not match the query ID or the question of the query with that of the response. This oversight makes applications using ldns for (stub) resolver functionality over UDP vulnerable to off-path poisoning attacks. The drill tool, which is shipped with ldns, is also affected by this vulnerability.
Defensive priority
HIGH
Recommended defensive actions
- Update to a version of ldns that is not vulnerable (e.g., version 1.9.1 or later).
- Use ldns with TCP instead of UDP if possible.
- Implement additional validation and verification of DNS responses in applications using ldns.
Evidence notes
The CVE-2026-10846 vulnerability was published on [cve-org] and detailed information can be found at [nvd]. Additional references include [ref-4] and [ref-5].
Sources and references
Verified primary and authoritative sources
-
CVE-2026-10846 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-10846
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-10846 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-10846
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.