VulnSea

nlnetlabs has 9 CVEs on record between 2021 and 2026. Cadence is steady at roughly 4 per quarter. The busiest recent month was May 2026 with 4. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. Most affected products: unbound (5), nsd (4).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
4 prev 4

Products

  • unbound 5
  • nsd 4
9
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

nlnetlabs vulnerabilities

CVEs affecting nlnetlabs, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-19538High· 7.5
3w ago

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

Twilightnlnetlabs · nsdEPSS 0.30%via NVD
CVE-2026-19401High· 7.5
3w ago

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512)

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned number of DNS Cookie options (17 when UDP payload size is 512). By continuously crashing the …

Twilightnlnetlabs · nsdEPSS 0.36%via NVD
CVE-2026-18916High· 7.5
3w ago

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the remote client can denial all TCP service to this NSD instance.

Twilightnlnetlabs · nsdEPSS 0.36%via NVD
CVE-2026-18664Critical· 9.1
3w ago

When ranges are used for access control (i.e

When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were meant t…

Midnightnlnetlabs · nsdEPSS 0.33%via NVD
CVE-2026-42959High· 7.5
4mo ago

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, t…

Twilightnlnetlabs · unboundEPSS 0.78%via NVD
CVE-2026-44390Medium· 5.3
4mo ago

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records t…

Sunlitnlnetlabs · unboundEPSS 0.63%via NVD
CVE-2026-42534Medium· 5.3
4mo ago

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and…

Sunlitnlnetlabs · unboundEPSS 0.58%via NVD
CVE-2026-41292High· 7.5
4mo ago

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threa…

Twilightnlnetlabs · unboundEPSS 0.72%via NVD
CVE-2019-25031Medium· 5.9
5y ago

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound softw…

Sunlitnlnetlabs · unboundEPSS 1.3%via NVD
nlnetlabs vulnerabilities (CVEs) · VulnSea