Nbdkit

Vendor:

First CVE: Mar 18, 2021 · Active for 5 years

5
Total CVEs
More Total CVEs than 79% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 62% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 12% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Nbdkit over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 18, 2021
5 years ago
Most Recent CVE
Jun 9, 2025
413 days ago

CVE Severity & Scoring

Nbdkit5 CVEs
All CVEs352,785 CVEs
LowMedium
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (60.0%)
High2 (40.0%)
Unknown0 (0.0%)
User Interaction
None5 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (80.0%)
High0 (0.0%)
None1 (20.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
There's a flaw in the nbdkit server when handling responses from its plugins regarding the status of data blocks. If a client makes a specific request for a very large data range,
Jun 9, 20256.522NONO
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. Thi
Mar 18, 20216.522NONO
A flaw exists in the nbdkit "blocksize" filter that can be triggered by a specific type of client request. When a client requests block status information for a very large data ran
Jun 9, 20256.521NONO
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work
Mar 18, 20213.717NONO
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_S
Mar 2, 20223.116NONO

Exploit Exposure

Signals from CVEs in this product scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (5 CVEs).

Media Mentions

Signals from CVEs in this product scope (5 CVEs).

Top CNAs Publishing CVEs For Nbdkit

Top CWEs

Versions

No cataloged versions.