PatchSiren

NLnet Labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL NLnet Labs CVE published 2026-09-16

CVE-2026-81642

A vulnerability was found in NLnet Labs Unbound up to and including 1.26.0 in the DNSSEC validator. This vulnerability enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.

HIGH NLnet Labs CVE published 2026-08-26

CVE-2026-19538

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T09:16:46.057Z and has not been modified since then. This vulnerability, CVE-2026-19538, involves BLOCKED access control list items on the proxy protocol port that can be bypassed when connecting over TCP or TLS and sending the query twice on a kept-open connection. The vulnerability has a high CV [truncated]

MEDIUM NLnet Labs CVE published 2026-08-26

CVE-2026-18916

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T09:16:45.597Z and has not been modified since then. CVE-2026-18916 is a denial of service vulnerability in NSD instances. Remote clients can crash NSD serve children by throttling the TCP receive window after a TCP query, potentially leading to denial of all TCP service. The CVSS score of 6.9 ind [truncated]

HIGH NLnet Labs CVE published 2026-08-26

CVE-2026-18664

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T09:16:45.437Z and has not been modified since then. This vulnerability affects NSD, leading to incorrect comparisons of IP addresses with ranges on little-endian systems. As a result, IPs meant to be allowed may be denied, and IPs meant to be denied could be allowed. The issue arises from the end [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-56416

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:22.090Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects Unbound up to and including version 1.25.1, allowing for potential heap buffer overflows when processing DNSSEC-covered records with absent second domain names.

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-55991

A remote unauthenticated client can trigger a libngtcp2 assertion failure and terminate the Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query due to an erroneous error value passed to libngtcp2. This vulnerability affects Unbound 1.22.0 through 1.25.1 and has a CVSS score of 5.9 with a severity of MEDIUM. The vulnerability is caused by an erroneous error value passed t [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-55990

A vulnerability was found in Unbound DNSCrypt. When the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. This faulty configuration can lead to a garbage dereference when an unauthenticated client sends [truncated]

HIGH NLnet Labs CVE published 2026-07-22

CVE-2026-55973

CVE-2026-55973 is a HIGH severity vulnerability in Unbound DNS resolver software. When 'dns-error-reporting: yes' is set, an attacker can exploit the EDNS Report-Channel option to cause a stack buffer overflow, potentially terminating the daemon. One ordinary upstream response from a delegated zone controlled by the attacker is sufficient to exploit this vulnerability. The vulnerability affects Unbound ve [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-55717

A denial of service vulnerability exists in Unbound versions 1.10.0 through 1.25.1. When 'serve-expired: yes' is set along with a 'response-ip: <net> redirect' or 'response-ip-data: <net> CNAME <target>' rule, a remote client can crash the daemon. This is achieved by controlling any delegated domain and exploiting the 'serve-expired-client-timeout' callback, leading to a NULL pointer dereference and serve [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-55708

A vulnerability in NLnet Labs Unbound 1.6.0 up to and including 1.25.1 allows for the creation of a bare local zones tree for an already configured named view through the 'unbound-control' interface. This creation omits adding default-protected zones, potentially allowing queries for default-protected names to escape to the public DNS. The vulnerability impacts users of Unbound in versions 1.6.0 through 1 [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-54478

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:21.177Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects Unbound versions 1.18.0 through 1.25.1, specifically when configured with a 'proxy-protocol-port' interface and 'answer-cookie: yes'. The server-cookie SipHash is compute [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-52863

A memory corruption vulnerability exists in Unbound 1.25.0-1.25.1. The issue arises from a shallow copy of the view name in effect, which could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. This vulnerability requires specific configurations, including 'respip'/'rpz' modules, 'access-control-view', and subquery modules like 'respip CNAME re [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-50252

CVE-2026-50252 is a DNS cache poisoning vulnerability affecting Unbound versions 1.4.22 through 1.25.1. The issue arises when load balancing policies depend on the source UDP port while revealing their outcome, undermining the secrecy of DNS transactions. This occurs when the SO_REUSEPORT configuration option is enabled, allowing for deterministic assignment of incoming DNS queries to specific worker thre [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-50251

CVE-2026-50251 is a vulnerability in Unbound DNS software that allows a remote attacker to trigger a cache clear of the message and rrset caches indefinitely, potentially leading to a denial-of-service condition. The vulnerability exists when 'unwanted-reply-threshold' is enabled and a malicious actor controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0. This can cause Unbound to loop and c [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-50243

A vulnerability was found in NLnet Labs Unbound, a popular DNS resolver. The issue occurs when Unbound is configured with the 'respip' module and a 'response-ip' redirect rule or RPZ file with an RPZ-IP trigger. In such cases, the rewriting handler does not verify the security status of the upstream answer. Consequently, a BOGUS A/AAAA answer can be rewritten to point to an operator's configured IP, poten [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-50046

CVE-2026-50046 is a denial of service vulnerability affecting Unbound versions 1.15.0 through 1.25.1. The vulnerability occurs when handling DNS-over-TLS (DoT) forwarded queries. A malicious actor could exploit this by querying records in a specific zone while keeping Unbound under pressure, leading to a daemon crash. The vulnerability arises from the TLS server name used for DoT forwarded queries being t [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-46582

A vulnerability in Unbound 1.6.0 up to and including 1.25.1 allows for DNSSEC secure cache poisoning through replay of a wildcard rrset. This issue arises when a replay of a wildcard rrset as another piece of data could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. The vulnerability occurs [truncated]

HIGH NLnet Labs CVE published 2026-07-22

CVE-2026-44690

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:19.153Z and has not been modified since then. This vulnerability affects NLnet Labs Unbound versions 1.7.0 through 1.25.1, allowing for cache poisoning attacks due to insufficient validation of the RRSIG.Labels field. The vulnerability has a high CVSS score of 7.5 and is classified as HIGH [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-44687

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:19.040Z and has not been modified since then. This vulnerability affects Unbound versions 1.13.2 through 1.25.1, where an off-by-one error in 'harden-below-nxdomain' logic could allow an attacker to bypass DNSSEC NXDOMAIN checks. Organizations should verify their configurations and consider [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-44621

A vulnerability in Unbound's libunbound, when configured with 'unwanted-reply-threshold', could lead to abrupt termination if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup'. This function is absent from the function call allow list, resulting in a fatal exit of libunbound and eventual termination of the embedding application.

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-42955

CVE-2026-42955 is a 'ghost domain names' vulnerability in Unbound 1.16.2 through 1.25.1. An adversary controlling a ghost zone can query a vulnerable Unbound to extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. In configurations with 'harden-referral-path: yes', no client query is required. This vulnerability is a variant of CVE-2026-40622, which only address [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-41637

A vulnerability in Unbound 1.22.0-1.25.1 can cause DNS-over-QUIC (DoQ) queries to be improperly accounted for, leading to service degradation for new clients. This occurs when client-terminated DoQ queries are not properly counted, causing an inflation of waiting replies for in-flight resolution queries. Exploitation requires Unbound to be compiled with DoQ support and configured to listen on a QUIC port. [truncated]

HIGH NLnet Labs CVE published 2026-07-22

CVE-2026-40691

CVE-2026-40691 is a denial-of-service vulnerability in Unbound versions 1.9.0 through 1.25.1. The issue arises when a DNSCrypt query is received over TCP, and the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. This can lead to a crash of the resolver. The vulnerability requires Unbound to be compiled with DNSCrypt support and the 'dnscrypt:' c [truncated]

HIGH NLnet Labs CVE published 2026-07-22

CVE-2026-32665

A remote denial of service vulnerability exists in NLnet Labs Unbound 1.22.0 through 1.25.1 when DNS-over-QUIC (DoQ) is enabled. The vulnerability allows a remote client to bypass the 'quic-size' limit, leading to excessive memory allocation and potential denial of service for new DoQ clients. This issue arises from the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypassing [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-14586

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:15.020Z and has not been modified since then. This vulnerability affects Unbound versions 1.22.0 to 1.25.1 with DNS-over-QUIC (DoQ) support enabled. The vulnerability can lead to server termination and denial of service under high concurrency and pressure in DoQ environments. The issue aris [truncated]

HIGH NLnet Labs CVE published 2026-06-10

CVE-2026-10846

CVE-2026-10846 is a HIGH-severity vulnerability in NLnet Labs ldns, a DNS library used for DNS resolution. Versions 1.2.0 through 1.9.0 are affected when used as a (stub) resolver over UDP. The vulnerability allows for off-path poisoning attacks due to a lack of matching between query and response source addresses, ports, query IDs, and questions.

HIGH NLnet Labs CVE published 2026-06-08

CVE-2026-49234

CVE-2026-49234 is a HIGH severity vulnerability in Routinator that causes a crash when a specifically crafted non-UTF-8 string is sent as a select-asn query parameter to the /api/v1/origins endpoint. This issue only affects users who allow API access from untrusted networks. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH NLnet Labs CVE published 2026-06-08

CVE-2026-49232

CVE-2026-49232 is a high-severity vulnerability in Routinator, a software used for RPKI-based BGP route validation. The vulnerability has a CVSS score of 8.7 and can cause a denial of service (DoS) condition when accepting incoming HTTP or RTR connections. An attacker can trigger this condition by opening a large number of connections to the HTTP or RTR server, causing the software to exit on any error, i [truncated]

MEDIUM NLnet Labs CVE published 2026-05-20

CVE-2026-44608

CVE-2026-44608 describes a locking inconsistency in NLnet Labs Unbound that can lead to a heap use-after-free and eventual crash when specific conditions line up: the resolver is multi-threaded, an RPZ zone uses rpz-nsip or rpz-nsdname triggers, and an XFR reload of that RPZ zone is happening at the same time another thread reads the zone. The issue does not apply to local RPZ files. NLnet Labs states tha [truncated]

MEDIUM NLnet Labs CVE published 2026-05-20

CVE-2026-44390

CVE-2026-44390 is a denial-of-service issue in NLnet Labs Unbound. According to the vendor advisory and NVD, Unbound up to and including 1.25.0 can spend a considerable amount of CPU time applying name compression to replies containing very large RRsets, especially when the records do not share a suffix above the root. In well-orchestrated attacks, this can degrade performance and eventually lead to servi [truncated]