Search CVE reports


Toggle filters

71 – 80 of 44746 results

Status is adjusted based on your filters.


CVE-2026-50252

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the...

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50251

Medium priority
Needs evaluation

In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such...

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50248

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the...

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50243

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting...

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50046

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp')....

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50045

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the...

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-46582

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later...

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-44690

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a...

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-44687

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the...

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-44621

Medium priority
Needs evaluation

With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to...

1 affected package

unbound

Package 22.04 LTS
unbound Needs evaluation
Show less packages