<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 12:00:38 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-369353</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-369353</link>
      <description>EUVD-2026-369353</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-369353</guid>
    </item>
    <item>
      <title>fkie_cve-2026-85501</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-85501</link>
      <description>&lt;p&gt;Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term &amp;#39;ReTrap&amp;#39;. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where  the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where  responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term &amp;#39;ReTrap&amp;#39;. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where  the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where  responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-85501</guid>
    </item>
    <item>
      <title>GHSA-qwgf-hj58-8c2w</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qwgf-hj58-8c2w</link>
      <description>&lt;p&gt;Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term &amp;#39;ReTrap&amp;#39;. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where  the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where  responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term &amp;#39;ReTrap&amp;#39;. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where  the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where  responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qwgf-hj58-8c2w</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-85501 — Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-85501</link>
      <description>msrc_CVE-2026-85501</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-85501</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11930-1 — libunbound8-1.26.1-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11930-1</link>
      <description>&lt;p&gt;libunbound8-1.26.1-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libunbound8-1.26.1-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11930-1</guid>
    </item>
    <item>
      <title>RHSA-2026:68590 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:68590</link>
      <description>&lt;p&gt;unbound: Unbound: Denial of Service via &amp;#39;serve-expired&amp;#39; code path bypass unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution unbound: Unbound: Denial of Service via use-after-free in DoQ stream output buffer unbound: Unbound: Denial of Service via continuous queries on TCP/DoT connection unbound: Unbound: Heap buffer overflow via malicious DNSSEC response unbound: Unbound: Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;unbound: Unbound: Denial of Service via &amp;#39;serve-expired&amp;#39; code path bypass unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution unbound: Unbound: Denial of Service via use-after-free in DoQ stream output buffer unbound: Unbound: Denial of Service via continuous queries on TCP/DoT connection unbound: Unbound: Heap buffer overflow via malicious DNSSEC response unbound: Unbound: Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup unbound: Unbound: Denial of Service via algorithmic complexity attacks on DNSSEC&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:68590</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-85501</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-85501</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:18.04:LTS: unbound, Ubuntu:Pro:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound, Ubuntu:24.04:LTS: unbound, Ubuntu:26.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term &amp;#39;ReTrap&amp;#39;. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where  the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where  responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:18.04:LTS: unbound, Ubuntu:Pro:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound, Ubuntu:24.04:LTS: unbound, Ubuntu:26.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term &amp;#39;ReTrap&amp;#39;. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where  the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where  responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-85501</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-3392 — Unbound: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3392</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Unbound ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Speicher zu korrumpieren, einen Denial of Service zu verursachen oder Code auszuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Unbound ausnutzen, um Sicherheitsmaßnahmen zu umgehen, Speicher zu korrumpieren, einen Denial of Service zu verursachen oder Code auszuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-3392</guid>
    </item>
  </channel>
</rss>
