NLnet Labs is a research and development organization focused on DNS infrastructure and Internet standards, with its primary vulnerability profile centered on the Net-DNS product line. The recurring signal reflects DNS protocol implementation and configuration complexities rather than a broad product portfolio; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by NLnet Labs over time
Of all the CVEs published by NLnet Labs as a CNA, 0.0% affect products that NLnet Labs develops as a vendor.
Of all the CVEs published that affect products developed by NLnet Labs, 0.0% are self-published by NLnet Labs as a CNA.
Signals from CVEs in this vendor scope (99 CVEs).
99 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50387HIGH Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D | Feb 14, 2024 | 7.5 | 78 | NO | NO |
CVE-2026-33278CRITICAL NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a resu | May 20, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-12244HIGH If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 6551 | Jun 25, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-42960CRITICAL NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies i | May 20, 2026 | 10.0 | 38 | NO | NO |
CVE-2026-55973HIGH In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read an | Jul 22, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-12490HIGH When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed whe | Jun 25, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-12246HIGH NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is writt | Jun 25, 2026 | 8.1 | 36 | NO | NO |
CVE-2026-12245HIGH NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS | Jun 25, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-42959HIGH NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When | May 20, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-42944HIGH NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Paddin | May 20, 2026 | 7.5 | 34 | NO | NO |
Signals from CVEs in this vendor scope (99 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by NLnet Labs.
Media articles that mention a CVE ID that affects a product developed by NLnet Labs — matched by CVE ID, not by vendor name.