Resolver Vulnerability in nlnet Labs ldns Affects Network Applications
CVE-2026-10846

8.2HIGH

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-10846?

The ldns library from NLnet Labs is susceptible to a vulnerability where it fails to match the query's destination address and port with the response's source address and port. This issue occurs in versions 1.2.0 through 1.9.0 when ldns is utilized in applications as a DNS (stub) resolver over UDP. Additionally, the lack of checks on the query ID and question matching between query and response enhances the risk of off-path poisoning attacks. The drill tool included with ldns is also affected by this vulnerability. Developers and network administrators should take precaution to assess the impact and apply necessary security measures.

Affected Version(s)

ldns 1.2.0 < 1.9.1

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pablo Ruiz from 'codecome.ai'
.