Yasuhiro Morishita[verified]@OrangeMorishitaDisclosure
The post discloses two CVEs affecting nsd resolution: CVE‑2026‑12244 causes a heap overflow that could lead to RCE via a crafted SVCB record, while CVE‑2026‑12245 involves a use‑after‑free in DoT implementation that may be exploited for DoS.
日本レジストリサービス(JPRS)@JPRS_officialDisclosure
A notice announces the release of new vulnerability information for four CVEs, but provides no further details about exploits, patches, or technical specifics.
Open Source Security mailing list@oss_securityPatch
NLnet Labs announced that four high‑severity CVEs affecting NSD have been patched in version 4.14.3, detailing the types of vulnerabilities (heap overflow, DNS‑over‑TLS denial, stack write, and certificate bypass).
日本レジストリサービス(JPRS)@JPRS_officialDisclosure
The newsletter announces the publication of vulnerability information for several CVEs, indicating a disclosure-focused communication.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
This brief notice announces a heap use‑after‑free vulnerability in NSD 4.13.0 that leads to a server crash, with no evidence of exploitation, PoC, or patch details provided.