← All tracked CVEs
Updated 04:00
Low severity
Low90d SLAOur service-level agreement (SLA) gives a low vulnerability a fix within 90 days of publication. 53 CVEs are tracked here: open, or fixed in the last 30 days.
| CVE | Status | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|
| Fixed within SLA | Unbound 1.6.0–1.25.1 cache poisoning via DNSSEC wildcard replay on serve-expired path | secure-packages-25.11 | Jul 27, 2026 | Oct 25, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.22.0-1.25.1 DoQ termination miscount inflates waiting replies, causing query drops | secure-packages-25.11 | Jul 27, 2026 | Oct 25, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Unbound 1.18–1.25.1 proxy-protocol miscomputes DNS cookie, enabling off-path spoofed replays | secure-packages-25.11 | Jul 27, 2026 | Oct 25, 2026 | Jul 29, 2026 | 2 days |