Every CVE whose affected-product data names Nlnetlabs Unbound, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (64)
CVE-2026-42960 — CVSS 10.0 (critical): NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section…
CVE-2019-25034 — CVSS 9.8 (critical): Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor…
CVE-2019-25035 — CVSS 9.8 (critical): Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability…
CVE-2026-33278 — CVSS 9.8 (critical): NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and…
CVE-2019-25038 — CVSS 9.8 (critical): Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a…
CVE-2019-25039 — CVSS 9.8 (critical): Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a…
CVE-2019-25042 — CVSS 9.8 (critical): Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a…
CVE-2019-25032 — CVSS 9.8 (critical): Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a…
CVE-2019-25033 — CVSS 9.8 (critical): Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a…
CVE-2026-50252 — CVSS 9.3 (critical): In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that…
CVE-2026-32665 — CVSS 7.5 (high): In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional…
CVE-2026-44690 — CVSS 7.5 (high): In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache…
CVE-2026-42959 — CVSS 7.5 (high): NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a…
CVE-2019-16866 — CVSS 7.5 (high): Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source…
CVE-2026-42944 — CVSS 7.5 (high): NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID…
CVE-2019-25036 — CVSS 7.5 (high): Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a…
CVE-2019-25037 — CVSS 7.5 (high): Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes…
CVE-2019-25040 — CVSS 7.5 (high): Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a…
CVE-2019-25041 — CVSS 7.5 (high): Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a…
CVE-2026-40622 — CVSS 7.5 (high): NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could…
CVE-2020-10772 — CVSS 7.5 (high): An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable…
CVE-2020-12662 — CVSS 7.5 (high): Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains…
CVE-2020-12663 — CVSS 7.5 (high): Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
CVE-2026-41292 — CVSS 7.5 (high): NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of…
CVE-2009-3602 — CVSS 7.5 (high): Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be…
CVE-2026-55973 — CVSS 7.5 (high): In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18)…
CVE-2022-3204 — CVSS 7.5 (high): A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The…
CVE-2023-50387 — CVSS 7.5 (high): Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of…
CVE-2024-1931 — CVSS 7.5 (high): NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain…
CVE-2026-40691 — CVSS 7.5 (high): In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails…
CVE-2019-18934 — CVSS 7.3 (high): Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially…
CVE-2022-30698 — CVSS 6.5 (medium): NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability…
CVE-2022-30699 — CVSS 6.5 (medium): NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability…
CVE-2026-50248 — CVSS 6.5 (medium): In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS…
CVE-2026-55991 — CVSS 5.9 (medium): In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled…
CVE-2026-44621 — CVSS 5.9 (medium): With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold'…
CVE-2026-52863 — CVSS 5.9 (medium): In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow…
CVE-2026-56444 — CVSS 5.9 (medium): In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-time…
CVE-2026-50046 — CVSS 5.9 (medium): In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a…
CVE-2019-25031 — CVSS 5.9 (medium): Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a…
CVE-2026-55990 — CVSS 5.9 (medium): In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there…
CVE-2026-44608 — CVSS 5.9 (medium): NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met…
CVE-2026-55717 — CVSS 5.9 (medium): In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect'…
CVE-2020-28935 — CVSS 5.5 (medium): NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local…
CVE-2026-32792 — CVSS 5.3 (medium): NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support…
CVE-2026-42534 — CVSS 5.3 (medium): NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade…
CVE-2026-42923 — CVSS 5.3 (medium): NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the…
CVE-2017-15105 — CVSS 5.3 (medium): A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record…
CVE-2026-44390 — CVSS 5.3 (medium): NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs…
CVE-2026-50045 — CVSS 5.3 (medium): In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can…
CVE-2026-50251 — CVSS 5.3 (medium): In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero)…
CVE-2024-8508 — CVSS 5.3 (medium): NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs…
CVE-2009-4008 — CVSS 5.0 (medium): Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to…
CVE-2010-0969 — CVSS 5.0 (medium): Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service…
CVE-2026-56416 — CVSS 4.8 (medium): In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered…
CVE-2011-1922 — CVSS 4.3 (medium): daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote…
CVE-2014-8602 — CVSS 4.3 (medium): iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of…
CVE-2026-42955 — CVSS 3.7 (low): In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family…
CVE-2026-50243 — CVSS 3.7 (low): In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator…
CVE-2026-44687 — CVSS 3.7 (low): In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC…
CVE-2026-54478 — CVSS 3.7 (low): In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie…
CVE-2026-41637 — CVSS 3.7 (low): In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by…
CVE-2026-46582 — CVSS 3.7 (low): In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered…
CVE-2026-55708 — CVSS 3.1 (low): In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a…