CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
Information published.
Categories: Microsoft
CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound
Information published.
Categories: Microsoft
CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out
Information published.
Categories: Microsoft
CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments
Information published.
Categories: Microsoft
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
Information published.
Categories: Microsoft
CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
Information published.
Categories: Microsoft
CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use
Information published.
Categories: Microsoft
CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
Information published.
Categories: Microsoft
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
Information published.
Categories: Microsoft
CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
Information published.
Categories: Microsoft
CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated
Information published.
Categories: Microsoft
CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
Information published.
Categories: Microsoft
CVE-2026-52863 Memory corruption could lead to crash and denial of service
Information published.
Categories: Microsoft
CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control'
Information published.
Categories: Microsoft
CVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
Information published.
Categories: Microsoft
CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Information published.
Categories: Microsoft
CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts
Information published.
Categories: Microsoft
CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
Information published.
Categories: Microsoft
CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow
Information published.
Categories: Microsoft


