CVE-2026-12246
NLnet Labs NSD, nsd
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
- CVSS
- 7.2
- EPSS
- 0.30% 22.3% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.25