Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.1 LOW
CVE-2026-55708 — Privacy/configuration issue when adding local data in views through 'unbound-control'

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view …

unbound | Misconfiguration
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
3.7 LOW
CVE-2026-54478 — DNS Cookie bypass when combined with proxy-protocol use

In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the p…

unbound | Misconfiguration
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
2.1 LOW
CVE-2026-53910 — Heap-based Buffer Overflow in GNU diffutils

diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can resu…

diffutils | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.9 MEDIUM
CVE-2026-52863 — Memory corruption could lead to crash and denial of service

In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory c…

unbound | Memory Corruption
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
9.3 CRITICAL
CVE-2026-50252 — Possible cache poisoning attack by mapping source port population per thread

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balan…

unbound | Misconfiguration
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
5.3 MEDIUM
CVE-2026-50251 — Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush

In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on sy…

unbound | Denial of Service
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
6.5 MEDIUM
CVE-2026-50248 — BOGUS configured primary hostname accepted for XFR in auth/rpz zones

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A mal…

unbound | Misconfiguration
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
6.3 MEDIUM
CVE-2026-50243 — 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL

In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with a…

unbound | Misconfiguration
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
5.9 MEDIUM
CVE-2026-50046 — Possible heap use-after-free in an error path when a DoT forwarded query is jostled out

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by ano…

unbound | Race Condition
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
5.3 MEDIUM
CVE-2026-50045 — 'max-global-quota' reset by DNSSEC validation restarts

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query t…

unbound | Denial of Service
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
3.7 LOW
CVE-2026-46582 — A wildcard replay, as another piece of data, triggers poisoning in the serve expired repl…

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored …

unbound | Information Disclosure
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
7.5 HIGH
CVE-2026-44690 — Cross-zone wildcard cache poisoning via RRSIG.labels manipulation

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cach…

unbound | Information Disclosure
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
3.7 LOW
CVE-2026-44687 — Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a leg…

In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's s…

unbound | Misconfiguration
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
5.9 MEDIUM
CVE-2026-44621 — Libunbound applications configured with 'unwanted-reply-threshold' could eventually be ab…

With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is r…

unbound | Denial of Service
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
3.7 LOW
CVE-2026-42955 — Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-ti…

In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost …

unbound | Denial of Service
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
3.7 LOW
CVE-2026-41637 — Degradation of resolution service from improperly accounted client-terminated DNS-over-QU…

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of r…

unbound | Denial of Service
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
7.5 HIGH
CVE-2026-40691 — Packet of death for DNSCrypt over TCP

In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer si…

unbound | Memory Corruption
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
7.5 HIGH
CVE-2026-32665 — Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the pe…

unbound | Denial of Service
Jul 22, 2026 Jul 24, 2026
Jul 22, 2026
Jul 24, 2026
5.3 MEDIUM
CVE-2026-16560 — 389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call to refer to the sam…

Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
9.1 CRITICAL
CVE-2026-16232 — Check Point SmartConsole Improper Authentication Vulnerability - [Actively Exploited]

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with ful…

Jul 22, 2026 Jul 23, 2026
Jul 22, 2026
Jul 23, 2026
Showing 20 of 9045 Results