Search CVE reports


Toggle filters

1 – 10 of 57 results


CVE-2026-19538

Medium priority
Needs evaluation

The BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting over TCP or TLS and sending the query twice on connection that is kept open.

1 affected package

nsd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nsd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-18664

Medium priority
Needs evaluation

When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little endian systems, IPs that were meant to be allowed may be denied, and, IPs that were...

1 affected package

nsd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nsd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-19401

Medium priority
Needs evaluation

(Any remote client can crash a (debugging/non-release build type) NSD s ...)

1 affected package

nsd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nsd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-18916

Medium priority
Needs evaluation

(Any remote client can crash a NSD serve child, by throttling the TCP r ...)

1 affected package

nsd

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
nsd Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-52682

Medium priority
Needs evaluation

[A crafted DNS packet can cause increased memory and CPU consumption]

3 affected packages

dnsdist, pdns, pdns-recursor

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pdns Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
pdns-recursor Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-54340

Medium priority
Needs evaluation

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 9265bdd, there is an HTTP/2 state amplification issue that combines HPACK decompression amplification with Slowloris-style stream stalling....

2 affected packages

h2o, dnsdist

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
h2o Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dnsdist Not affected Needs evaluation Not affected Not affected Not affected
Show less packages

CVE-2026-44453

Medium priority
Needs evaluation

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the...

2 affected packages

h2o, dnsdist

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
h2o Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dnsdist Not affected Needs evaluation Not affected Not affected Not affected
Show less packages

CVE-2026-44452

Medium priority
Needs evaluation

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 8dc37cb, when h2o receives a ClientHello message over TLS or QUIC and it contains a zero-length SNI extension, the h2o server runs over...

2 affected packages

h2o, dnsdist

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
h2o Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dnsdist Not affected Needs evaluation Not affected Not affected Not affected
Show less packages

CVE-2026-55213

Medium priority
Needs evaluation

h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate...

2 affected packages

h2o, dnsdist

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
h2o Not in release Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dnsdist Not affected Needs evaluation Not affected Not affected Not affected
Show less packages

CVE-2026-42004

Medium priority
Needs evaluation

An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that...

1 affected package

dnsdist

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Needs evaluation Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages