Known Vulnerabilities for Unbound by NLnet Labs
Listed below are 10 of the newest known vulnerabilities associated with "Unbound" by "NLnet Labs".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-67328 json | @better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that ... | Not Provided | 2026-08-01 | 2026-08-01 |
| CVE-2026-64453 json | In the Linux kernel, the following vulnerability has been resolved: usb: misc: usbio: fix disconnect UAF in client teardown ... | Not Provided | 2026-07-25 | 2026-07-25 |
| CVE-2026-64228 json | In the Linux kernel, the following vulnerability has been resolved: net: ethtool: phy: avoid NULL deref when PHY driver is u... | Not Provided | 2026-07-24 | 2026-07-24 |
| CVE-2026-63834 json | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: restrict number of unacked list en... | Not Provided | 2026-07-19 | 2026-07-19 |
| CVE-2026-59224 json | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, backend/open_webui/rou... | Not Provided | 2026-07-09 | 2026-07-10 |
| CVE-2026-56444 json | In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expi... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-56416 json | In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-cov... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-55991 json | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (i... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-55990 json | In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' file... | Not Provided | 2026-07-22 | 2026-07-22 |
| CVE-2026-55973 json | In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel opti... | Not Provided | 2026-07-22 | 2026-07-22 |