NLnet Labs

First CVE: Dec 7, 2020Active for: 6 years
65
CVEs Published
More CVEs Published than 64% of tracked CNAs
9.3
Avg CVEs / Year
More Avg CVEs / Year than 51% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by NLnet Labs as a CNA, 0.0% affect products that NLnet Labs develops as a vendor.

100.0%
Self-reported: 0Third-party: 65

Of all the CVEs published that affect products developed by NLnet Labs, 0.0% are self-published by NLnet Labs as a CNA.

100.0%
Self-published: 0Published by other CNAs: 1

Trends Over Time

The number and severity of CVEs published by NLnet Labs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 7, 2020
5 years ago
Most Recent CVE
Jul 22, 2026
3 days ago

Top CVEs

All CVEs published by NLnet Labs as a CNA, regardless of affected vendor or product.

65 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a resu
May 20, 20269.843NONO
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies i
May 20, 202610.041NONO
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 6551
Jun 25, 20268.840NONO
In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When
Jul 22, 20269.338NONO
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read an
Jul 22, 20267.536NONO
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed whe
Jun 25, 20267.536NONO
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is writt
Jun 25, 20268.136NONO
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS
Jun 25, 20267.535NONO
NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When
May 20, 20267.534NONO
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Paddin
May 20, 20267.534NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA65 CVEs
Severity distribution among all CVEs352,708 CVEs
LowMediumHighCritical
Attack Vector
Local4 (6.2%)
Network59 (90.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.5%)
Attack Complexity
Low48 (73.8%)
High17 (26.2%)
Unknown0 (0.0%)
User Interaction
None62 (95.4%)
Unknown0 (0.0%)
Required3 (4.6%)
Privileges Required
Low8 (12.3%)
High1 (1.5%)
None56 (86.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (65 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by NLnet Labs as a CNA.

Media Mentions

Media articles that mention a CVE ID published by NLnet Labs as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs