VYPR

DNS Server

by Technitium

CVEs (7)

  • CVE-2022-30258CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V2 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would…

  • CVE-2022-30257CriNov 21, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Technitium DNS Server through 8.0.2 that allows variant V1 of unintended domain name resolution. A revoked domain name can still be resolvable for a long time, including expired domains and taken-down malicious domains. The effects of an exploit would…

  • CVE-2022-48256HigJan 13, 2023
    risk 0.49cvss 7.5epss 0.01

    Technitium DNS Server before 10.0 allows a self-CNAME denial-of-service attack in which a CNAME loop causes an answer to contain hundreds of records.

  • CVE-2026-42255HigApr 26, 2026
    risk 0.47cvss 7.2epss 0.00

    Technitium DNS Server before 15.0 allows DNS traffic amplification via cyclic name server delegation.

  • CVE-2026-45557MedMay 19, 2026
    risk 0.38cvss 5.8epss 0.00

    Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network traffic. Fixed in 15.0.

  • CVE-2021-43105MedMar 28, 2022
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the bailiwick checking function in Technitium DNS Server <= v7.0 exists that allows specific malicious users to inject `NS` records of any domain (even TLDs) into the cache and conduct a DNS cache poisoning attack.

  • CVE-2026-36478Jun 26, 2026
    risk 0.00cvss epss 0.00

    An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll, TechnitiumLibrary.Net/Dns/DnsClient.cs components