← All tracked CVEs
Updated 18:00
last 30 days
910 fixed within SLA
| CVE | Status | Severity | Summary | Release | Clock started | Deadline | Fixed | Time to fix |
|---|---|---|---|---|---|---|---|---|
| Fixed within SLA | Medium | Unbound DoT TLS handshake use-after-free leads to daemon crash (1.15.0–1.25.1) | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Medium | Unbound 1.22–1.25.1 upstream packets per query exceed max-global-quota for deep DNSSEC names | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Low | DNSSEC wildcard replay cache poisoning in Unbound 1.6.0–1.25.1 serve-expired path | secure-packages-26.05 | Jul 27, 2026 | Oct 25, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | High | Unbound 1.7.0–1.25.1 RRSIG.Labels validation bug enables NSEC sibling zone cache poisoning | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Low | Unbound 1.13.2–1.25.1 harden-below-nxdomain off-by-one returns parent NXDOMAIN, shadowing stub/forward zones | secure-packages-26.05 | Jul 27, 2026 | Oct 25, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Medium | libunbound <=1.25.1 aborts when unwanted-reply-threshold invokes disallowed libworker_alloc_cleanup | secure-packages-26.05 | Jul 27, 2026 | Sep 10, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Low | Unbound 1.16.2–1.25.1 A/AAAA glue bug extends ghost-domain window; CVE-2026-40622 variant | secure-packages-26.05 | Jul 27, 2026 | Oct 25, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | Low | Unbound 1.22–1.25.1 DoQ termination misaccounting inflates waiters, causing silent query drops | secure-packages-26.05 | Jul 27, 2026 | Oct 25, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | High | Unbound 1.9.0–1.25.1 DNSCrypt TCP path overflow causes heap corruption and DoS | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days | |
| Fixed within SLA | High | Unbound downstream DoQ initial streams bypass quic-size, causing remote memory-accounting DoS (v1.22–1.25.1) | secure-packages-26.05 | Jul 27, 2026 | Aug 11, 2026 | Jul 29, 2026 | 2 days |