NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.
History

Wed, 10 Jun 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 10 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
References

Wed, 10 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Nlnetlabs
Nlnetlabs ldns
Vendors & Products Nlnetlabs
Nlnetlabs ldns

Wed, 10 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
Description NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address and port. Furthermore not the query ID, neither the question of the query is matched with that of the response. This makes applications, that use ldns for (stub) resolver functionality over UDP, vulnerable for off-path poisoning attacks. The drill tool, which is shipped with ldns, suffers from this vulnerability.
Title Insufficient verification that responses belong to a query
Weaknesses CWE-346
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NLnet Labs

Published: 2026-06-10T06:37:59.538Z

Updated: 2026-06-10T14:45:59.412Z

Reserved: 2026-06-04T12:06:54.996Z

Link: CVE-2026-10846

cve-icon Vulnrichment

Updated: 2026-06-10T11:15:23.130Z

cve-icon NVD

Status : Received

Published: 2026-06-10T07:16:24.443

Modified: 2026-06-10T12:16:24.957

Link: CVE-2026-10846

cve-icon Redhat

No data.