CVE-2026-12246Disclosure(nlnetlabs / nsd)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nlnetlabs nsd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-120

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nsd

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 5 classified signals
  • Peaked 3d ago at 2 mentions (2026-06-25); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
nsd

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-26: 1Mentions · 2026-06-29: 1Mentions · 2026-07-06: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 106-2506-2606-2907-06
Signal classification1 categories
Disclosure
5100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-252
Disclosure2
2026-06-261
Disclosure1
2026-06-291
Disclosure1
2026-07-061
Disclosure1
Full discourse5 posts
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【注意喚起】NSDの脆弱性情報が公開されました(CVE-2026-12244、CVE-2026-12245、CVE-2026-12246、CVE-2026-12490) https://jprs.jp/tech/security/2026-06-29-nsd.html

    Post summary

    The notice reports the release of vulnerability information for NSD, listing four CVE identifiers, but does not provide technical details, PoC, or exploitation status.

    031601.4K
    1.3K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    NLnet Labs NSD: 4 "high" CVEs fixed in 4.14.3 https://www.openwall.com/lists/oss-security/2026/06/25/9 CVE-2026-12244: Heap overflow with crafted SVCB RR CVE-2026-12245: Denial of DNS over TLS service CVE-2026-12246: Out of bounds stack write with crafted APL RR CVE-2026-12490: Bypass of client certificate

    Post summary

    NLnet Labs announces that four high‑severity CVEs in NSD have been patched in release 4.14.3, detailing heap overflow, DoS, stack write, and client certificate bypass issues.

    01050777
    4.7K followersView on X
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【メールマガジン(FROM JPRS)】最新号を掲載しました。 通常号 vol.1252「NSDの脆弱性情報が公開されました(CVE-2026-12244、CVE-2026-12245、CVE-2026-12246、CVE-2026-12490)、他2件」など https://jprs.jp/mail/backnumber/2026/260706.html

    Post summary

    The JPRS newsletter announces that NSD has publicly disclosed vulnerability information for several CVEs, but provides no Proof‑of‑Concepts, exploitation details, patches, or other technical specifics.

    00031367
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    (続き) CVE-2026-12246:APLレコードの実装不具合でセカンダリサーバーのゾーンデータを破壊可能。 CVE-2026-12490:XFR over TLS(XoT)の実装不具合でクライアント証明書による認証がバイパスされる。

    Post summary

    The snippet reports two new CVEs: one that allows zone data destruction via an APL record flaw, and another that bypasses client‑certificate authentication in XFR over TLS.

    10020189
    4.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - NSD APL RR stack overflow during zone write (CVE-2026-12246) NSD 4.14.0 contains a memory corruption flaw in its handling of APL (Address Prefix List) resource records when serializing/writing a zone to disk. The root cause is improper input validation/bounds checking on the address-family length field, allowing an overlong value to drive a stack-based buffer overflow. An attacker can exploit this by getting a specially crafted APL record into a zone that NSD later writes out (e.g., via zone provisioning, automation pipelines, or any workflow that imports untrusted zone content), with no elevated OS privileges required beyond the ability to influence zone data. Successful exploitation can overwrite up to 111 attacker-controlled bytes on the stack, potentially leading to denial of service or, in worst cases, code execution depending on platform mitigations. 👉 Affected: NSD 4.14.0 | Upgrade to No fix yet — treat as suspicious

    Post summary

    A high‑impact stack‑based buffer overflow flaw in NSD 4.14.0 allows exploitation via crafted APL records leading to DoS or code execution, with no fix yet available.

    0000080
    228 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnlnetlabsnsd---

Explore more