CVE-2026-12246
Out of bounds stack write with crafted APL RR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
| CWE | CWE-120 CWE-20 |
| Vendor | nlnet labs |
| Product | nsd |
| Published | Jun 25, 2026 |
| Last Updated | Jun 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for nlnet labs nsd
Be the first to know when new unknown vulnerabilities affecting nlnet labs nsd are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
NLnet Labs / NSD
4.14.0 < 4.14.3
References
Credits
Qifan Zhang from Palo Alto Networks Haruki Oyama from Waseda University zhangph