CVE-2023-26249: Nic Knot Resolver

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client query may lead to a hundred TCP connection attempts if a DNS server closes connections without providing a response.

Affected products

  • Nic Knot Resolver: before 5.6.0 (fixed in 5.6.0)

Published 2023-02-21. Last modified 2026-06-17.