nlnetlabs
43 known vulnerabilities affecting nlnetlabs products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-33278 | Medium | 1.3% | 9.8 | NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability… | |
| CVE-2026-42944 | Medium | 0.8% | 7.5 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability… | |
| CVE-2026-42959 | Medium | 0.8% | 7.5 | NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vu… | |
| CVE-2026-41292 | Medium | 0.7% | 7.5 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degrada… | |
| CVE-2026-49233 | Medium | 0.4% | 7.5 | Routinator does not properly check the module component of rsync URIs, which are… | |
| CVE-2026-49235 | Medium | 0.4% | 7.5 | When Routinator encounters a file via RRDP using a specifically crafted Document… | |
| CVE-2026-18916 | Medium | 0.4% | 7.5 | Any remote client can crash a NSD serve child, by throttling the TCP receive win… | |
| CVE-2026-19401 | Medium | 0.4% | 7.5 | Any remote client can crash a (debugging/non-release build type) NSD serve child… | |
| CVE-2026-18664 | Medium | 0.3% | 9.1 | When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), bec… | |
| CVE-2026-19538 | Medium | 0.3% | 7.5 | The BLOCKED access control list items that are evaluated to deny access on the t… | |
| CVE-2026-40691 | Medium | 0.3% | 7.5 | In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received o… | |
| CVE-2026-32665 | Medium | 0.3% | 7.5 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-ove… | |
| CVE-2026-55973 | Medium | 0.3% | 7.5 | In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporti… | |
| CVE-2026-49234 | Medium | 0.3% | 7.5 | When sending a specifically crafted non-UTF-8 string as select-asn query paramet… | |
| CVE-2026-42960 | Medium | 0.2% | 10.0 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning… | |
| CVE-2026-50252 | Medium | 0.2% | 9.3 | In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is rand… | |
| CVE-2026-10846 | Medium | 0.1% | 7.5 | NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applicati… | |
| CVE-2026-44690 | Medium | 0.1% | 7.5 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation … | |
| CVE-2026-40622 | Medium | 0.1% | 7.5 | NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability… | |
| CVE-2019-25031 | Low | 1.3% | 5.9 | Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers… | |
| CVE-2026-44390 | Low | 0.6% | 5.3 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when h… | |
| CVE-2026-42534 | Low | 0.6% | 5.3 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the… | |
| CVE-2026-42923 | Low | 0.3% | 5.3 | NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the… | |
| CVE-2026-32792 | Low | 0.3% | 5.3 | NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of serv… | |
| CVE-2026-50045 | Low | 0.3% | 5.3 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query f… | |
| CVE-2026-41637 | Low | 0.3% | 3.7 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-o… | |
| CVE-2026-52863 | Low | 0.3% | 5.9 | In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'r… | |
| CVE-2026-55990 | Low | 0.3% | 5.9 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' cla… | |
| CVE-2026-56444 | Low | 0.3% | 5.9 | In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configu… | |
| CVE-2026-44608 | Low | 0.3% | 5.9 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking incon… | |
| CVE-2026-50251 | Low | 0.3% | 5.3 | In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-t… | |
| CVE-2026-44621 | Low | 0.2% | 5.9 | With NLnet Labs Unbound up to and including version 1.25.1, applications using l… | |
| CVE-2026-50046 | Low | 0.2% | 5.9 | In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name use… | |
| CVE-2026-55717 | Low | 0.2% | 5.9 | In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: ye… | |
| CVE-2026-55991 | Low | 0.2% | 5.9 | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticate… | |
| CVE-2026-44687 | Low | 0.2% | 3.7 | In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones w… | |
| CVE-2026-42955 | Low | 0.2% | 3.7 | In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability… | |
| CVE-2026-46582 | Low | 0.2% | 3.7 | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard r… | |
| CVE-2026-54478 | Low | 0.2% | 3.7 | In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on… | |
| CVE-2026-55708 | Low | 0.2% | 3.1 | In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' an… | |
| CVE-2026-50248 | Low | 0.1% | 6.5 | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone ha… | |
| CVE-2026-56416 | Low | 0.1% | 4.8 | In NLnet Labs Unbound up to and including version 1.25.1, when the validator bui… | |
| CVE-2026-50243 | Low | 0.1% | 3.7 | In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configur… |