Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Pablo Ruiz

#33083of 56,330
8.2Total CVSS
Vulnerabilities · 1
PT-2026-48381
8.2
2026-06-09
Nlnet · Ldns · CVE-2026-10846
**Name of the Vulnerable Software and Affected Versions** NLnet Labs ldns versions 1.2.0 through 1.9.0 **Description** When used in applications as a stub resolver over UDP, the software fails to match the query destination address and port with the response source address and port. Additionally, it does not verify that the query ID or the query question matches the response. This deficiency allows for off-path poisoning attacks, where an attacker sends forged responses to the resolver. The drill tool included with the software is also affected. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.