CVEs we hold for Nlnet
Records whose assigning authority named Nlnet as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-85501Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSECNLnet Labs Unbound
CVE-2026-81642Heap buffer overflow and possible Remote Code Execution when digesting DNSKEYNLnet Labs Unbound
CVE-2026-80225Possible degradation of service from continuous queries on the same TCP/DoT connectionNLnet Labs Unbound
CVE-2026-64194Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chainsNLNETLABS Net::DNS
CVE-2026-64193Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERRORNLNETLABS Net::DNS
CVE-2026-56444Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual…NLnet Labs Unbound
CVE-2026-56416Possible heap buffer overflow when validator canonicalizes RDATA that contains domain nameNLnet Labs Unbound
CVE-2026-55991Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2NLnet Labs Unbound
CVE-2026-55717'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crashNLnet Labs Unbound
CVE-2026-55708Privacy/configuration issue when adding local data in views through 'unbound-control'NLnet Labs Unbound
CVE-2026-50252Possible cache poisoning attack by mapping source port population per threadNLnet Labs Unbound
CVE-2026-50251Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flushNLnet Labs Unbound
CVE-2026-50248BOGUS configured primary hostname accepted for XFR in auth/rpz zonesNLnet Labs Unbound
CVE-2026-50243'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAILNLnet Labs Unbound
CVE-2026-50046Possible heap use-after-free in an error path when a DoT forwarded query is jostled outNLnet Labs Unbound
CVE-2026-49234Routinator crashes on specifically crafted ASN strings in the APINLnet Labs Routinator
CVE-2026-49232Routinator exits when accepting an incoming HTTP or RTR connection failsNLnet Labs Routinator
CVE-2026-46582A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply pathNLnet Labs Unbound
CVE-2026-44687Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAINNLnet Labs Unbound
CVE-2026-44621Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminatedNLnet Labs Unbound
CVE-2026-44390Unbounded name compression in certain cases causes degradation of serviceNLnet Labs Unbound
CVE-2026-42960Possible cache poisoning via promiscuous records for the authority sectionNLnet Labs Unbound
CVE-2026-42955Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation…NLnet Labs Unbound
CVE-2026-41637Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queriesNLnet Labs Unbound
CVE-2026-32665Remote DNS-over-QUIC denial of service due to `quic-size` budget bypassNLnet Labs Unbound
CVE-2026-14586Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environmentsNLnet Labs Unbound
CVE-2025-11411Possible domain hijacking via promiscuous records in the authority sectionNLnet Labs Unbound
CVE-2025-0638Routinator crashes when illegal characters are present in manifest file namesNLnet Labs Routinator
CVE-2024-1622Routinator terminates when RTR connection is reset too quickly after openingNLnet Labs Routinator
CVE-2022-30699Novel "ghost domain names" attack by updating almost expired delegation informationNLnet Labs Unbound
CVE-2022-30698Novel "ghost domain names" attack by introducing subdomain delegationsNLnet Labs Unbound
CVE-2021-41531Invalid RPKI data could disable Route Origin Validation on RTR clients.NLnet Labs Routinator
79 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.