Nic maintains a focused set of critical DNS and network infrastructure products including Knot Resolver, BIRD, Foris, and Knot CMS that operate in trusted network positions and often handle untrusted input at scale. Vulnerabilities affecting the vendor concentrate in input-validation and resource-management classes—such as improper input validation, unthrottled resource allocation, and inefficient algorithmic complexity—that are characteristic of protocol-parsing and routing software operating under high or adversarial load, and tend toward moderate severity outcomes. Defenders should prioritize updates for these infrastructure components, particularly resolver and routing implementations; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nic over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50387HIGH Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D | Feb 14, 2024 | 7.5 | 78 | NO | NO |
CVE-2021-3346CRITICAL Foris before 101.1.1, as used in Turris OS, lacks certain HTML escaping in the login template. | Jan 29, 2021 | 9.8 | 28 | NO | NO |
CVE-2022-40188HIGH Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must | Sep 23, 2022 | 7.5 | 27 | NO | NO |
CVE-2026-49943MEDIUM CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() func | Jun 2, 2026 | 6.3 | 25 | NO | NO |
CVE-2019-19331HIGH knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficientl | Dec 16, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-16159HIGH BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communicatio | Sep 9, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-10191HIGH A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, open | Jul 16, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-10190HIGH A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-exist | Jul 16, 2019 | 7.5 | 25 | NO | NO |
CVE-2021-40083HIGH Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof). | Aug 25, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-1110HIGH A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service. | Mar 30, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nic.
Media articles that mention a CVE ID that affects a product developed by Nic — matched by CVE ID, not by vendor name.