CVE-2018-1000002: Nic Knot Resolver

Low severity, CVSS 3.7. EPSS: 1.1% chance of exploitation in the next 30 days.

Improper input validation bugs in DNSSEC validators components in Knot Resolver (prior version 1.5.2) allow attacker in man-in-the-middle position to deny existence of some data in DNS via packet replay.

Affected products

  • Nic Knot Resolver: before 1.5.2 (fixed in 1.5.2)

Published 2018-01-22. Last modified 2026-06-17.