Vulnerabilidades en NLnet Labs

77 resultados
Análisis Vexday

NLnet Labs apresenta volume elevado de vulnerabilidades recentes (20 das 40 CVEs nos últimos 90 dias), com 2 críticas catalogadas, mas nenhuma sob exploração ativa conhecida. A fraqueza dominante (CWE-349) concentra os riscos em uma classe específica, sugerindo problemas sistemáticos que demandam remediação priorizada nos componentes afetados.

CVE-2026-42960MEDIUMPossible cache poisoning via promiscuous records for the authority sectionEPSS 0.3%CVE-2026-18664HIGHWrong interpretation of ACL rangesEPSS 0.3%CVE-2026-14586MEDIUMAssertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environmentsEPSS 0.3%CVE-2026-46582LOWA wildcard replay, as another piece of data, triggers poisoning in the serve expired reply pathEPSS 0.3%CVE-2026-54478LOWDNS Cookie bypass when combined with proxy-protocol useEPSS 0.2%CVE-2026-19538HIGHBypass of BLOCKED ACL items on proxy protocol port over TCP or TLSEPSS 0.2%CVE-2026-12490HIGHBypass of client certificate verification with transfer over TLSEPSS 0.2%CVE-2025-5994HIGHCache poisoning via the ECS-enabled Rebirthday AttackEPSS 0.2%CVE-2026-40622MEDIUMAnother 'ghost domain names' attack variantEPSS 0.2%CVE-2026-50248MEDIUMBOGUS configured primary hostname accepted for XFR in auth/rpz zonesEPSS 0.2%CVE-2026-55708LOWPrivacy/configuration issue when adding local data in views through 'unbound-control'EPSS 0.2%CVE-2026-50252MEDIUMPossible cache poisoning attack by mapping source port population per threadEPSS 0.2%CVE-2026-77955MEDIUMPossible ZONEMD verification bypass windowEPSS 0.1%CVE-2026-10846HIGHInsufficient verification that responses belong to a queryEPSS 0.1%CVE-2026-44690HIGHCross-zone wildcard cache poisoning via RRSIG.labels manipulationEPSS 0.1%CVE-2026-56416MEDIUMPossible heap buffer overflow when validator canonicalizes RDATA that contains domain nameEPSS 0.1%CVE-2026-50243MEDIUM'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAILEPSS 0.1%