Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
NLnet Labs Unbound up to and including version 1.26.0 contains a heap buffer overflow vulnerability triggered during CNAME synthesis when enforcing a max TTL value in the packet buffer. This flaw can cause progressive heap memory corruption and, depending on system and compilation options, may lead to remote code execution. Join the discussion | GCVE Database | 09/16/2026, 09:30:28 UTC Added: 09/24/2026, 06:09:27 UTC |
0 CVE-2026-85501 is a medium severity vulnerability in NLnet Labs Unbound DNS resolver up to version 1.26.0. It involves allocation of resources without limits or throttling, enabling algorithmic complexity attacks on DNSSEC validation. The attacks exploit mechanisms such as triple matching of Zone, Algo, and KeyTag, iterative chain-of-trust validation for deeply nested domains, excessive invalid NSEC records, and validation of the ADDITIONAL section by default. These cause significant computational overhead and potential degradation of service. Join the discussion | CVE Database V5 | 09/16/2026, 09:17:00 UTC Added: 09/16/2026, 08:47:05 UTC |
0 CVE-2026-80225 is a medium severity vulnerability in NLnet Labs Unbound up to version 1.26.0. It involves a denial-of-service condition caused by unrestricted consecutive reads in the TCP/DoT reading procedure. An attacker able to stream many distinct uncached DNS names over a TCP/DoT connection can monopolize a worker's event loop, causing service degradation. No confidentiality or integrity impacts are reported. Join the discussion | CVE Database V5 | 09/16/2026, 09:17:00 UTC Added: 09/16/2026, 08:47:05 UTC |
0 NLnet Labs Unbound versions 1.20.0 through 1.26.0 contain a vulnerability in the 'serve-expired' code path that allows a double decrement of the 'wait-limit' counter per client IP. This flaw can be exploited by an attacker controlling an authoritative zone with short TTLs to bypass a DNS query rate-limiting countermeasure introduced for DNSBomb (CVE-2024-33655). The attacker can maintain the per-client counter at or below the configured limit indefinitely, allowing an arbitrary number of pending queries from a single source IP. The vulnerability has a CVSS score of 3.7 and is classified as medium severity. Join the discussion | CVE Database V5 | 09/16/2026, 09:17:00 UTC Added: 09/16/2026, 08:47:05 UTC |
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If the prerequisites are satisfied (possible RPZ drop or heavy client traffic), a malicious actor can trigger the vulnerability with a single DoH connection and the appropriate traffic. Impact is limited as the reads are not user controlled and the use-after-free leads to early returns. However, a hardened allocator can catch the use-after-free and controllably terminate the process resulting to denial of service. Join the discussion | CVE Database V5 | 09/16/2026, 08:32:10 UTC Added: 09/16/2026, 08:47:05 UTC |
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Coupled with a compression pointer that points to the overwritten value and invalidates the domain name, it leads to an error path that does not properly move the buffer position and allows for the heap buffer overflow. Since this is heavily reliant on heap memory layout, results are memory corruption that eventually leads to a crash and under specific systems and compilation options remote code execution. Join the discussion | CVE Database V5 | 09/16/2026, 08:31:59 UTC Added: 09/16/2026, 08:47:05 UTC |
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound. Join the discussion | CVE Database V5 | 09/16/2026, 08:30:58 UTC Added: 09/16/2026, 08:47:05 UTC |
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability. Join the discussion | CVE Database V5 | 09/16/2026, 08:30:15 UTC Added: 09/16/2026, 08:47:05 UTC |
NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retransmission buffer keeps a shallow pointer into the output buffer for as long as a STREAM frame may be resent. On a client RESET_STREAM, the output buffer is freed but ngtcp2 still holds the matching retransmission entries. The next PTO timeout makes ngtcp2 re-encode the STREAM frame and copy from the freed buffer. A malicious actor that can query Unbound over DoQ and that withholds ACKs, sends RESET_STREAM, and waits for PTO, reaches this use-after-free with no privilege. This leads to retransmissions against freed memory and eventually an abnormal server exit under a 20-query spray. Join the discussion | CVE Database V5 | 09/16/2026, 08:29:52 UTC Added: 09/16/2026, 08:47:05 UTC |
0 In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads. Join the discussion | CVE Database V5 | 09/16/2026, 08:29:39 UTC Added: 09/16/2026, 08:47:05 UTC |
Showing 1 to 10 of 38 results