Several vulnerabilities were found in NLnet Labs NSD. The overview of the vulnerabilities with a brief description is:
CVE-2026-12244 - severity: HIGH Heap overflow and crash with crafted SVCB RR
CVE-2026-12245 - severity: HIGH Denial of DNS over TLS service by any DoT client
CVE-2026-12246 - severity: HIGH Out of bounds stack write with crafted APL RR
CVE-2026-12490 - severity: HIGH Bypass of client certificate verification with transfer over TLS
The patches are tested to apply/work on 4.14.2
Best regards, -- Willem, on behalf of the NSD team.
Last updated 29 June 2026