Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 18

Количество 18

github логотип

GHSA-6522-r5fq-99gw

4 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-44390

4 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-44390

4 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-44390

4 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the comp

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-44390

4 месяца назад

Unbounded name compression in certain cases causes degradation of service

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-44390

4 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerabil ...

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260713-80-0016

2 месяца назад

Уязвимость unbound

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2026-10812

4 месяца назад

Уязвимость DNS-сервера unbound, связанная с чрезмерным потреблением ресурсов в цикле, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260713-73-0016

2 месяца назад

Уязвимость unbound

CVSS3: 5.3
EPSS: Низкий
rocky логотип

RLSA-2026:37282

около 2 месяцев назад

Important: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:36777

около 2 месяцев назад

Important: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:36320

около 2 месяцев назад

Important: unbound security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-37282

3 месяца назад

ELSA-2026-37282: unbound security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36777

3 месяца назад

ELSA-2026-36777: unbound security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36320

2 месяца назад

ELSA-2026-36320: unbound security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21083-1

3 месяца назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2369-1

3 месяца назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2281-1

4 месяца назад

Security update for unbound

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6522-r5fq-99gw

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 5.3
1%
Низкий
4 месяца назад
ubuntu логотип
CVE-2026-44390

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 5.3
1%
Низкий
4 месяца назад
redhat логотип
CVE-2026-44390

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 7.5
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-44390

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the comp

CVSS3: 5.3
1%
Низкий
4 месяца назад
msrc логотип
CVE-2026-44390

Unbounded name compression in certain cases causes degradation of service

CVSS3: 5.3
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-44390

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerabil ...

CVSS3: 5.3
1%
Низкий
4 месяца назад
redos логотип
ROS-20260713-80-0016

Уязвимость unbound

CVSS3: 5.3
1%
Низкий
2 месяца назад
fstec логотип
BDU:2026-10812

Уязвимость DNS-сервера unbound, связанная с чрезмерным потреблением ресурсов в цикле, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
1%
Низкий
4 месяца назад
redos логотип
ROS-20260713-73-0016

Уязвимость unbound

CVSS3: 5.3
1%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:37282

Important: unbound security update

около 2 месяцев назад
rocky логотип
RLSA-2026:36777

Important: unbound security update

около 2 месяцев назад
rocky логотип
RLSA-2026:36320

Important: unbound security update

около 2 месяцев назад
oracle-oval логотип
ELSA-2026-37282

ELSA-2026-37282: unbound security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-36777

ELSA-2026-36777: unbound security update (IMPORTANT)

3 месяца назад
oracle-oval логотип
ELSA-2026-36320

ELSA-2026-36320: unbound security update (IMPORTANT)

2 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:21083-1

Security update for unbound

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2369-1

Security update for unbound

3 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2281-1

Security update for unbound

4 месяца назад

Уязвимостей на страницу