Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

NLnet Labs

First CVE: Jun 25, 2007Active for: 19 yearsTotal CVEs: 99

NLnet Labs is a research and development organization focused on DNS infrastructure and Internet standards, with its primary vulnerability profile centered on the Net-DNS product line. The recurring signal reflects DNS protocol implementation and configuration complexities rather than a broad product portfolio; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
99
Total CVEs
Bottom 1%
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 2% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by NLnet Labs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 25, 2007
19 years ago
Most Recent CVE
Jul 22, 2026
3 days ago

Self-Reporting Analysis

Of all the CVEs published by NLnet Labs as a CNA, 0.0% affect products that NLnet Labs develops as a vendor.

100.0%
Self-reported: 0 (0.0%)
Third-party: 65 (100.0%)

Of all the CVEs published that affect products developed by NLnet Labs, 0.0% are self-published by NLnet Labs as a CNA.

100.0%
Self-published: 0 (0.0%)
Other CNAs: 1 (100.0%)

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (99 CVEs).

99 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-50387HIGH
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D
Feb 14, 20247.578NONO
CVE-2026-33278CRITICAL
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a resu
May 20, 20269.843NONO
CVE-2026-12244HIGH
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 6551
Jun 25, 20268.840NONO
CVE-2026-42960CRITICAL
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies i
May 20, 202610.038NONO
CVE-2026-55973HIGH
In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read an
Jul 22, 20267.536NONO
CVE-2026-12490HIGH
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed whe
Jun 25, 20267.536NONO
CVE-2026-12246HIGH
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is writt
Jun 25, 20268.136NONO
CVE-2026-12245HIGH
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS
Jun 25, 20267.535NONO
CVE-2026-42959HIGH
NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When
May 20, 20267.534NONO
CVE-2026-42944HIGH
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Paddin
May 20, 20267.534NONO
View all 99 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products99 CVEs
38%
42%
12%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (2.0%)
Network84 (84.8%)
Unknown11 (11.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low68 (68.7%)
High20 (20.2%)
Unknown11 (11.1%)
User Interaction
None86 (86.9%)
Unknown11 (11.1%)
Required2 (2.0%)
Privileges Required
Low6 (6.1%)
High1 (1.0%)
None81 (81.8%)
Unknown11 (11.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (99 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by NLnet Labs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by NLnet Labs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For NLnet Labs's Products

View all 4 CNAs →