Vulnerability Details CVE-2026-12246
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 17.8%
CVSS Severity
CVSS v3 Score 8.1
Products affected by CVE-2026-12246
-
cpe:2.3:a:nlnetlabs:nsd:4.14.0
-
cpe:2.3:a:nlnetlabs:nsd:4.14.1
-
cpe:2.3:a:nlnetlabs:nsd:4.14.2