CVE-2026-55990
published 2026-07-22CVE-2026-55990: In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.36%
28.0th percentile
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be compiled with DNSCrypt support ('--enable-dnscrypt').
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.7.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
| nlnetlabs | unbound | >= 1.7.0 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NLnet Labs Unbound up to 1.25.1 DNSCrypt null pointer dereference (WID-SEC-2026-2492)
vuldb·2026-09-11·CVSS 5.9
CVE-2026-55990 [MEDIUM] NLnet Labs Unbound up to 1.25.1 DNSCrypt null pointer dereference (WID-SEC-2026-2492)
A vulnerability labeled as critical has been found in NLnet Labs Unbound up to 1.25.1. Affected by this issue is some unknown functionality of the component DNSCrypt. The manipulation results in null pointer dereference.
This vulnerability is known as CVE-2026-55990. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
GHSA
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only
ghsa_unreviewed·2026-07-22
CVE-2026-55990 [MEDIUM] CWE-457 In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty configuration that goes unnoticed until triggered with the right client query. Unbound needs to be comp
Red Hat
unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration
vendor_redhat·2026-07-22·CVSS 5.9
CVE-2026-55990 [MEDIUM] CWE-125 unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration
unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration
A flaw was found in Unbound when configured with DNSCrypt support. An unauthenticated remote attacker could exploit a faulty configuration, where an imbalance between DNSCrypt provider certificate and secret key files leads to memory corruption. By sending a specially crafted network request, the attacker can cause a garbage dereference, leading to a server crash and a denial of service (DoS).
Statement: This Moderate flaw in Unbound can lead to a denial of service if the DNSCrypt feature is enabled and misconfigured. Exploitation requires Unbound to be compiled with DNSCrypt support, which is not a default setting in Red Hat products, and a specific mismatch between DNSCrypt provider certificate and secret
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55990 unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration [fedora-all]
bugzilla·2026-07-28·CVSS 5.9
CVE-2026-55990 [MEDIUM] CVE-2026-55990 unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration [fedora-all]
CVE-2026-55990 unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' byt
Bugzilla
CVE-2026-55990 unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration
bugzilla·2026-07-22·CVSS 5.9
CVE-2026-55990 [MEDIUM] CVE-2026-55990 unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration
CVE-2026-55990 unbound: NLnet Labs Unbound: Denial of Service via faulty DNSCrypt configuration
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that sends one UDP datagram of ≥ 68 bytes whose first 8 bytes are '0xdb' to 'dnscrypt-port' will use that garbage entry which leads to a garbage dereference killing the server. This is a silent faulty config
2026-07-22
Published