VulnSea

NLnet Labs has 11 CVEs on record. Disclosure cadence is accelerating: 11 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 9. The median CVSS is 5.9 (medium), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-122 (3).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.9
Publish → KEV
Last 90 days
11 prev 0

Products

  • Unbound 11
11
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

NLnet Labs vulnerabilities

CVEs affecting NLnet Labs, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-77955Medium· 4.4
5d ago

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…

SunlitNLnet Labs · UnboundEPSS 0.13%via NVD
CVE-2026-77860Low· 3.7
5d ago

In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was in…

In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was in…

SunlitNLnet Labs · UnboundEPSS 0.27%via NVD
CVE-2026-81642Critical· 9.1PoC
5d ago

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression po…

AbyssalNLnet Labs · UnboundEPSS 0.52%via NVD
CVE-2026-80225Medium· 5.3
5d ago

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of dis…

SunlitNLnet Labs · UnboundEPSS 0.31%via NVD
CVE-2026-78227Medium· 6.5
5d ago

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retrans…

SunlitNLnet Labs · UnboundEPSS 0.27%via NVD
CVE-2026-82720Medium· 5.9
5d ago

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a d…

SunlitNLnet Labs · UnboundEPSS 0.29%via NVD
CVE-2026-81634High· 7.5
5d ago

In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine

In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into …

TwilightNLnet Labs · UnboundEPSS 0.36%via NVD
CVE-2026-85501Medium· 5.3
5d ago

Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'

Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabiliti…

SunlitNLnet Labs · UnboundEPSS 0.31%via NVD
CVE-2026-82717High· 8.4
5d ago

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts whe…

TwilightNLnet Labs · UnboundEPSS 0.40%via NVD
CVE-2026-32665High· 7.5
2mo ago

Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, an…

TwilightNLnet Labs · UnboundEPSS 0.29%via CVEORG
CVE-2026-55991Medium· 5.9
2mo ago

Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) conne…

SunlitNLnet Labs · UnboundEPSS 0.24%via CVEORG
NLnet Labs vulnerabilities (CVEs) · VulnSea