NLnet Labs
First CVE: Dec 7, 2020Active for: 6 years
65
CVEs Published
More CVEs Published than 64% of tracked CNAs
9.3
Avg CVEs / Year
More Avg CVEs / Year than 51% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by NLnet Labs as a CNA, 0.0% affect products that NLnet Labs develops as a vendor.
100.0%
Self-reported: 0Third-party: 65
Of all the CVEs published that affect products developed by NLnet Labs, 0.0% are self-published by NLnet Labs as a CNA.
100.0%
Self-published: 0Published by other CNAs: 1
Trends Over Time
The number and severity of CVEs published by NLnet Labs over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 7, 2020
5 years ago
Most Recent CVE
Jul 22, 2026
3 days ago
Top CVEs
All CVEs published by NLnet Labs as a CNA, regardless of affected vendor or product.
65 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33278CRITICAL NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a resu | May 20, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-42960CRITICAL NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies i | May 20, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-12244HIGH If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 6551 | Jun 25, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-50252CRITICAL In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When | Jul 22, 2026 | 9.3 | 38 | NO | NO |
CVE-2026-55973HIGH In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read an | Jul 22, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-12490HIGH When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed whe | Jun 25, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-12246HIGH NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is writt | Jun 25, 2026 | 8.1 | 36 | NO | NO |
CVE-2026-12245HIGH NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS | Jun 25, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-42959HIGH NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When | May 20, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-42944HIGH NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Paddin | May 20, 2026 | 7.5 | 34 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA65 CVEs
12%
37%
46%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (6.2%)
Network59 (90.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.5%)
Attack Complexity
Low48 (73.8%)
High17 (26.2%)
Unknown0 (0.0%)
User Interaction
None62 (95.4%)
Unknown0 (0.0%)
Required3 (4.6%)
Privileges Required
Low8 (12.3%)
High1 (1.5%)
None56 (86.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (65 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by NLnet Labs as a CNA.
Media Mentions
Media articles that mention a CVE ID published by NLnet Labs as a CNA — matched by CVE ID, not by organization name.