Vendor
NLnet Labs vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 49 vulnerabilities in NLnet Labs: 0 in the last 7 days and 33 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-85501, was published on 16 September 2026. 2 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 33
- Critical, all time
- 2
- Exploited in the wild
- 0
About NLnet Labs
NLnet Labs is a non-profit foundation that develops open-source software and protocols for the core of the Internet.
NLnet Labs technologies
Latest NLnet Labs vulnerabilities
- CVE-2026-85501: NLnet Labs Unbound DNS complexity attacks via ReTrapmediumCVSS 5.3EPSS 0.5%
- CVE-2026-82720: NLnet Labs Unbound use-after-free in DNS-over-HTTPsmediumCVSS 5.9EPSS 0.4%
- CVE-2026-82717: NLnet Labs Unbound heap buffer overflow in CNAME synthesiscriticalCVSS 9.8EPSS 0.8%
- CVE-2026-81642: NLnet Labs Unbound DNSSEC validator buffer overflowcriticalCVSS 9.8EPSS 1.0%
- CVE-2026-81634: NLnet Labs Unbound heap buffer overflow in RRSet canonicalisationhighCVSS 7.5EPSS 0.5%
- CVE-2026-78227: NLnet Labs Unbound use-after-free in DNS-over-QUICmediumCVSS 6.5EPSS 0.3%
- CVE-2026-77955: NLnet Labs Unbound ZONEMD check bypass in delegated zonesmediumCVSS 4.4EPSS 0.2%
- CVE-2026-56444: NLnet Labs Unbound resource exhaustion in serve-expired logicmediumCVSS 5.9
- CVE-2026-56416: NLnet Labs Unbound heap buffer overflow in DNSSEC validatormediumCVSS 4.8
- CVE-2026-55991: NLnet Labs Unbound denial of service in DNS-over-QUICmediumCVSS 5.9
- CVE-2026-55990: NLnet Labs Unbound denial of service in DNSCryptmediumCVSS 5.9
- CVE-2026-55973: NLnet Labs Unbound stack overflow in DNS error reportinghighCVSS 7.5
- CVE-2026-55717: NLnet Labs Unbound DoS via NULL pointer dereference in serve-expired-client-timeoutmediumCVSS 5.9
- CVE-2026-55708: NLnet Labs Unbound insecure default initialization in unbound-controllowCVSS 3.1
- CVE-2026-54478: NLnet Labs Unbound DNS Cookie authentication bypass in PROXYv2lowCVSS 3.7
- CVE-2026-52863: NLnet Labs Unbound use-after-free in respip and dns64 modulesmediumCVSS 5.9
- CVE-2026-50252: NLnet Labs Unbound DNS cache poisoning via predictable UDP source portsinfoCVSS 5.7
- CVE-2026-50251: NLnet Labs Unbound cache flush via 0.0.0.0 glue recordsmediumCVSS 5.3
- CVE-2026-50248: NLnet Labs Unbound insufficient verification of XFR endpoints in RPZ zonesmediumCVSS 6.5
- CVE-2026-50243: NLnet Labs Unbound DNSSEC validation bypass in respip moduleinfoCVSS 6.3
- CVE-2026-50046: NLnet Labs Unbound use-after-free in DNS-over-TLS forwardingmediumCVSS 5.9
- CVE-2026-50045: NLnet Labs Unbound network amplification via global quota bypassmediumCVSS 5.3
- CVE-2026-46582: NLnet Labs Unbound DNS cache poisoning via wildcard replaylowCVSS 3.7
- CVE-2026-44690: NLnet Labs Unbound cache poisoning via aggressive NSEC processinghighCVSS 7.5
- CVE-2026-44687: NLnet Labs Unbound off-by-one error in harden-below-nxdomainlowCVSS 3.7
Most severe NLnet Labs vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-81642: NLnet Labs Unbound DNSSEC validator buffer overflowcriticalCVSS 9.8EPSS 1.0%
- CVE-2026-82717: NLnet Labs Unbound heap buffer overflow in CNAME synthesiscriticalCVSS 9.8EPSS 0.8%
- CVE-2026-81634: NLnet Labs Unbound heap buffer overflow in RRSet canonicalisationhighCVSS 7.5EPSS 0.5%
- CVE-2026-49234: NLnet Labs Routinator denial of service via malformed ASN query parameterhighCVSS 7.5EPSS 0.3%
- CVE-2026-55973: NLnet Labs Unbound stack overflow in DNS error reportinghighCVSS 7.5
- CVE-2026-44690: NLnet Labs Unbound cache poisoning via aggressive NSEC processinghighCVSS 7.5
- CVE-2026-40691: NLnet Labs Unbound heap overflow in DNSCrypt TCP handlerhighCVSS 7.5
- CVE-2026-32665: NLnet Labs Unbound denial of service in DNS-over-QUIChighCVSS 7.5
- CVE-2026-49233: NLnet Labs Routinator path traversal in rsync URI module componenthighCVSS 4EPSS 0.5%
- CVE-2026-49235: NLnet Labs Routinator denial of service via crafted RRDP DTDhighCVSS 4EPSS 0.5%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 26 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 7 | 2 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/nlnet-labs.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "NLnet Labs vulnerabilities", https://junglewise.ai/threats/vendors/nlnet-labs, 26 September 2026.