systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issue (i.e. there is no hostname to be sent)
Conclusion & alert: CVE-2018-21029 is rated High Exploit Risk (85.9/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.14%). Core evidence: 2 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +1.58% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ | |
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.56% | 3.14% | +1.58% |
| 2 | 2025-11-21 | 2.49% | 1.56% | -0.93% |
| 3 | 2025-11-18 | — | 2.49% | — |
Full EPSS history (12 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
low | CVE-2018-21029 low priority: Debian including 1 source packages (systemd), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2018-21029 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2018-21029 |
ubuntu
|
low | CVE-2018-21029 low priority: Ubuntu including 1 source packages (systemd), 6 status rows across 6 suites (bionic, disco, eoan, trusty, upstream, xenial): not-affected 4, ignored 1, needs-triage 1. | https://ubuntu.com/security/CVE-2018-21029 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| systemd_project | systemd | >= 239, < 244 | cpe:2.3:a:systemd_project:systemd:*:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://blog.cloudflare.com/dns-encryption-explained/ | Third Party Advisory |
| https://github.com/systemd/systemd/blob/v239/man/resolved.conf.xml#L199-L207 | Exploit Third Party Advisory |
| https://github.com/systemd/systemd/blob/v243/man/resolved.conf.xml#L196-L207 | Exploit Third Party Advisory |
| https://github.com/systemd/systemd/blob/v243/src/resolve/resolved-dnstls-gnutls.c#L62-L63 | Patch Third Party Advisory |
| https://github.com/systemd/systemd/issues/9397 | Issue Tracking Third Party Advisory |
| https://github.com/systemd/systemd/pull/13870 | Patch Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4NLJVOJMB6ANDILRLDZK26YGLYBEPHKY/ | |
| https://security.netapp.com/advisory/ntap-20191122-0002/ | Third Party Advisory |
| https://tools.ietf.org/html/rfc7858#section-4.1 | Third Party Advisory |