NLnetLabs develops a focused suite of DNS and DNSSEC infrastructure software—including Unbound resolver, Routinator RPKI validator, NSD nameserver, and related libraries—that occupies critical positions in recursive resolution and routing-security chains worldwide. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory-safety and protocol-parsing demands of DNS software operating at scale. The exposure recurs across products through weakness classes including integer overflows, out-of-bounds writes, infinite loops, uncontrolled resource consumption, and improper exception handling; these flaws are characteristic of performance-sensitive network daemons written in C and tasked with parsing untrusted DNS traffic. Defenders should treat this vendor's security advisories as priority patches for recursive resolvers and DNSSEC infrastructure, since these services are foundational to recursive query chains and are frequently visible to untrusted networks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nlnetlabs over time
Signals from CVEs in this vendor scope (99 CVEs).
99 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50387HIGH Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D | Feb 14, 2024 | 7.5 | 78 | NO | NO |
CVE-2026-33278CRITICAL NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a resu | May 20, 2026 | 9.8 | 43 | NO | NO |
CVE-2026-42960CRITICAL NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies i | May 20, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-50252CRITICAL In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When | Jul 22, 2026 | 9.3 | 38 | NO | NO |
CVE-2026-55973HIGH In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read an | Jul 22, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-12244HIGH If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 6551 | Jun 25, 2026 | 8.8 | 36 | NO | NO |
CVE-2026-42959HIGH NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When | May 20, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-42944HIGH NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Paddin | May 20, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-44690HIGH In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC proce | Jul 22, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-40691HIGH In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the de | Jul 22, 2026 | 7.5 | 33 | NO | NO |
Signals from CVEs in this vendor scope (99 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nlnetlabs.
Media articles that mention a CVE ID that affects a product developed by Nlnetlabs — matched by CVE ID, not by vendor name.