Nbdkit Project maintains a specialized network-block-device server library, a narrowly scoped but strategically positioned component in virtualization and storage infrastructures. Its disclosed vulnerabilities cluster around protocol-handling integrity, network-amplification conditions, integer arithmetic, and boundary-condition errors that are characteristic of low-level I/O and network-state machinery. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nbdkit Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-47711MEDIUM There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range, | Jun 9, 2025 | 6.5 | 22 | NO | NO |
CVE-2019-14851MEDIUM A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. Thi | Mar 18, 2021 | 6.5 | 22 | NO | NO |
CVE-2025-47712MEDIUM A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data ran | Jun 9, 2025 | 6.5 | 21 | NO | NO |
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work | Mar 18, 2021 | 3.7 | 17 | NO | NO |
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_S | Mar 2, 2022 | 3.1 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nbdkit Project.
Media articles that mention a CVE ID that affects a product developed by Nbdkit Project — matched by CVE ID, not by vendor name.