NLnet Labs vulnerabilities
20 CVEs tracked
NLnet Labs' Unbound DNS resolver is under significant scrutiny in the provided reports due to multiple critical vulnerabilities. Key themes include UDP source port predictability (CVE-2026-50252), cache poisoning via insufficient RRSIG validation (CVE-2026-44690), and bypass issues in DNS-over-QUIC (DoQ) configurations (CVE-2026-32665). Defenders should urgently review their configurations, especially if specific options like 'serve-expired', 'dns-error-reporting', or 'unwanted-reply-threshold' are enabled, and apply patches immediately.
Azərbaycanca: NLnet Labs-in məhsulu olan Unbound DNS resolver, təqdim olunan hesabatlarda kritik zəifliklərlə bağlı ciddi diqqət mərkəzindədir. Əsas mövzular UDP mənbə portunun proqnozlaşdırılması (CVE-2026-50252), RRSIG yoxlanışındakı qüsur səbəbilə keş zəhərlənməsi (CVE-2026-44690) və DNS-over-QUIC (DoQ) konfiqurasiyalarında yan keçid problemləridir (CVE-2026-32665). Müdafiəçilər xüsusilə `serve-expired`, `dns-error-reporting` və `unwanted-reply-threshold` kimi spesifik seçimlər aktiv olduqda konfiqurasiya fayllarını nəzərdən keçirməli və təcili olaraq yamaqları tətbiq etməlidirlər.
This vendor's CVEs20
- CVE-2026-55990EPSS 0.26%
- CVE-2026-55973EPSS 0.28%
- CVE-2026-55717EPSS 0.24%
- CVE-2026-55708EPSS 0.15%
- CVE-2026-54478EPSS 0.18%
- CVE-2026-52863EPSS 0.26%
- CVE-2026-50252EPSS 0.16%
- CVE-2026-50251EPSS 0.25%
- CVE-2026-50248EPSS 0.13%
- CVE-2026-50243EPSS 0.10%
- CVE-2026-50046EPSS 0.24%
- CVE-2026-50045EPSS 0.28%
- CVE-2026-46582EPSS 0.19%
- CVE-2026-44690EPSS 0.14%
- CVE-2026-44687EPSS 0.22%
- CVE-2026-44621EPSS 0.25%
- CVE-2026-42955EPSS 0.20%
- CVE-2026-41637EPSS 0.27%
- CVE-2026-32665EPSS 0.29%
- CVE-2026-14586EPSS 0.27%
This hub is built from skopnix's own reporting on NLnet Labs: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.