Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

github логотип

GHSA-6522-r5fq-99gw

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2026-44390

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-44390

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-44390

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the comp

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-44390

2 месяца назад

Unbounded name compression in certain cases causes degradation of service

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2026-44390

2 месяца назад

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerabil ...

CVSS3: 5.3
EPSS: Низкий
redos логотип

ROS-20260713-73-0016

19 дней назад

Уязвимость unbound

CVSS3: 5.3
EPSS: Низкий
rocky логотип

RLSA-2026:37282

3 дня назад

Important: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:36777

3 дня назад

Important: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:36320

3 дня назад

Important: unbound security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-37282

23 дня назад

ELSA-2026-37282: unbound security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36777

23 дня назад

ELSA-2026-36777: unbound security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36320

16 дней назад

ELSA-2026-36320: unbound security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21083-1

около 1 месяца назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2369-1

около 2 месяцев назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2281-1

около 2 месяцев назад

Security update for unbound

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-6522-r5fq-99gw

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 5.3
1%
Низкий
2 месяца назад
ubuntu логотип
CVE-2026-44390

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 5.3
1%
Низкий
2 месяца назад
redhat логотип
CVE-2026-44390

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the c...

CVSS3: 7.5
1%
Низкий
2 месяца назад
nvd логотип
CVE-2026-44390

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the comp

CVSS3: 5.3
1%
Низкий
2 месяца назад
msrc логотип
CVE-2026-44390

Unbounded name compression in certain cases causes degradation of service

CVSS3: 5.3
1%
Низкий
2 месяца назад
debian логотип
CVE-2026-44390

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerabil ...

CVSS3: 5.3
1%
Низкий
2 месяца назад
redos логотип
ROS-20260713-73-0016

Уязвимость unbound

CVSS3: 5.3
1%
Низкий
19 дней назад
rocky логотип
RLSA-2026:37282

Important: unbound security update

3 дня назад
rocky логотип
RLSA-2026:36777

Important: unbound security update

3 дня назад
rocky логотип
RLSA-2026:36320

Important: unbound security update

3 дня назад
oracle-oval логотип
ELSA-2026-37282

ELSA-2026-37282: unbound security update (IMPORTANT)

23 дня назад
oracle-oval логотип
ELSA-2026-36777

ELSA-2026-36777: unbound security update (IMPORTANT)

23 дня назад
oracle-oval логотип
ELSA-2026-36320

ELSA-2026-36320: unbound security update (IMPORTANT)

16 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21083-1

Security update for unbound

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2369-1

Security update for unbound

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2281-1

Security update for unbound

около 2 месяцев назад

Уязвимостей на страницу