Search CVE reports


Toggle filters

1 – 10 of 84 results


CVE-2026-85501

Medium priority
Needs evaluation

Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-82720

Medium priority
Needs evaluation

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-82717

Medium priority
Needs evaluation

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-81642

Medium priority
Needs evaluation

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-81634

Medium priority
Needs evaluation

In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-80225

Medium priority
Needs evaluation

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-78227

Medium priority
Needs evaluation

NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-77955

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-77860

Medium priority
Needs evaluation

In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-56444

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages