Skip to content
← All tracked CVEs

Updated 04:00

Low severity

Low90d SLA

Our service-level agreement (SLA) gives a low vulnerability a fix within 90 days of publication. 53 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
Fixed within SLAUnbound 1.6.0–1.25.1 cache poisoning via DNSSEC wildcard replay on serve-expired pathsecure-packages-25.11Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.22.0-1.25.1 DoQ termination miscount inflates waiting replies, causing query dropssecure-packages-25.11Jul 27, 2026Oct 25, 2026Jul 29, 20262 days
Fixed within SLAUnbound 1.18–1.25.1 proxy-protocol miscomputes DNS cookie, enabling off-path spoofed replayssecure-packages-25.11Jul 27, 2026Oct 25, 2026Jul 29, 20262 days