CVE-2026-50046
published 2026-07-22CVE-2026-50046: In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.36%
28.1th percentile
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.15.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
| nlnetlabs | unbound | >= 1.15.0 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling
vendor_redhat·2026-07-22·CVSS 5.9
CVE-2026-50046 [MEDIUM] CWE-416 unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling
unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling
A use-after-free flaw was found in Unbound's DNS-over-TLS (DoT) forwarded query handling. A remote attacker can exploit a timing error during TLS handshake failures on a server under load to trigger a daemon crash, resulting in a Denial of Service (DoS).
Statement: Unbound installations within Red Hat environments are vulnerable to a denial of service, leading to a daemon crash, only when specifically configured with DNS-over-TLS (DoT) forwarding or stub zones that include an `#authname` suffix. Exploitation by a remote attacker necessitates precise timing during transient network failures. Default Unbound configurations, which do not employ DoT forwarding or stub zones with `#authname`, are not
GHSA
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by anot
ghsa_unreviewed·2026-07-22
CVE-2026-50046 [MEDIUM] CWE-416 In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by anot
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerab
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-50046 unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling [fedora-all]
bugzilla·2026-07-30·CVSS 5.9
CVE-2026-50046 [MEDIUM] CVE-2026-50046 unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling [fedora-all]
CVE-2026-50046 unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The
Bugzilla
CVE-2026-50046 unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling
bugzilla·2026-07-22·CVSS 5.9
CVE-2026-50046 [MEDIUM] CVE-2026-50046 unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling
CVE-2026-50046 unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appro
2026-07-22
Published