Knot DNS is a focused authoritative DNS server implementation that, despite a narrow product scope, occupies a critical role in DNS infrastructure where it serves as the authoritative nameserver for many domains. The vendor's disclosed vulnerabilities have centered on the DNS service itself, reflecting the parsing and protocol-state complexity inherent to a nameserver implementation. Current exposure counts and severity data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Knot Dns over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6171HIGH Knot DNS before 2.3.0 allows remote DNS servers to cause a denial of service (memory exhaustion and slave server crash) via a large zone transfer for (1) DDNS, (2) AXFR, or (3) IXF | Feb 9, 2017 | 8.6 | 28 | NO | NO |
CVE-2017-11104MEDIUM Knot DNS before 2.4.5 and 2.5.x before 2.5.2 contains a flaw within the TSIG protocol implementation that would allow an attacker with a valid key name and algorithm to bypass TSIG | Jul 8, 2017 | 5.9 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Knot Dns.
Media articles that mention a CVE ID that affects a product developed by Knot Dns — matched by CVE ID, not by vendor name.