CVE-2018-10920: Nic Knot Resolver

Medium severity, CVSS 6.8. EPSS: 3.2% chance of exploitation in the next 30 days.

Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.

Affected products

  • Nic Knot Resolver: before 2.4.1 (fixed in 2.4.1)

Published 2018-08-02. Last modified 2026-06-17.