Vendorsnbdkit Projectnbdkitany version
Vulnerabilities

nbdkit Project nbdkit any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2019-14851
A denial of service vulnerability was discovered in nbdkit. A client issuing a certain sequence of commands could possibly trigger an assertion failure, causing nbdkit to exit. This issue only affected nbdkit versions 1.12.7, 1.14.1, and 1.15.1.
Published 2021-03-18 · Modified
6.5EPSS 0.010
CVE-2025-47712
Nbd: nbdkit: integer overflow triggers an assertion resulting in denial of service
Published 2025-06-09 · Modified
6.5EPSS 0.005
CVE-2025-47711
Nbdkit: nbdkit-server: off-by-one error when processing block status may lead to a denial of service
Published 2025-06-09 · Modified
6.5EPSS 0.005
CVE-2019-14850
A denial of service vulnerability was discovered in nbdkit 1.12.7, 1.14.1 and 1.15.1. An attacker could connect to the nbdkit service and cause it to perform a large amount of work in initializing backend plugins, by simply opening a connection to the service. This vulnerability could cause resource consumption and degradation of service in nbdkit, depending on the plugins configured on the server-side.
Published 2021-03-18 · Modified
3.7EPSS 0.016
CVE-2021-3716
A flaw was found in nbdkit due to to improperly caching plaintext state across the STARTTLS encryption boundary. A MitM attacker could use this flaw to inject a plaintext NBD_OPT_STRUCTURED_REPLY before proxying everything else a client sends to the server, potentially leading the client to terminate the NBD session. The highest threat from this vulnerability is to system availability.
Published 2022-03-02 · Modified
3.5EPSS 0.006