Search CVE reports


Toggle filters

911 – 920 of 44358 results

Status is adjusted based on your filters.


CVE-2026-52863

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50252

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50251

Medium priority
Needs evaluation

In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50248

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50243

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50046

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp')....

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-50045

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-46582

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-44690

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages

CVE-2026-44687

Medium priority
Needs evaluation

In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the...

1 affected package

unbound

Package 20.04 LTS
unbound Needs evaluation
Show less packages