CVE-2026-12246: Nlnetlabs Nsd

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.

Affected products

  • Nlnetlabs Nsd: from 4.14.0, before 4.14.3 (fixed in 4.14.3)

Published 2026-06-25. Last modified 2026-06-26.