CVE-2026-56444
published 2026-07-22CVE-2026-56444: In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout >…
PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.26%
17.6th percentile
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expired perform the correct decrement. Since the counter is never decremented in such scenario, it can reach the maximum limit and new clients for duplicate in-flight queries are silently dropped resulting in degradation of resolution service. A malicious actor can exploit the vulnerability by querying the resolver for a client-controlled slow-on-demand authoritative zone that can drive the counter past the threshold. Shipped defaults for 'serve-expired-client-timeout: 1800' and 'discard-timeout: 1900' make the branch unreachable.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.20.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
| nlnetlabs | unbound | >= 1.20.0 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NLnet Labs Unbound up to 1.25.1 Serve Expired Logic resource consumption (EUVD-2026-47685 / WID-SEC-2026-2492)
vuldb·2026-09-11·CVSS 5.9
CVE-2026-56444 [MEDIUM] NLnet Labs Unbound up to 1.25.1 Serve Expired Logic resource consumption (EUVD-2026-47685 / WID-SEC-2026-2492)
A vulnerability classified as problematic has been found in NLnet Labs Unbound up to 1.25.1. This issue affects some unknown processing of the component Serve Expired Logic. Performing a manipulation results in resource consumption.
This vulnerability was named CVE-2026-56444. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
GHSA
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values
ghsa_unreviewed·2026-07-22
CVE-2026-56444 [MEDIUM] CWE-772 In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expired perform the correct decrement. Since the counter is never decremented in such scenario, it can reach the maximum limit and new clients for duplicate in-flight queries are silently dropped resulting in degradation of resolution service. A malicious actor can exploit the vulnerability by querying the resolver for a client-controlled slow-on-demand authoritative zone that
Red Hat
unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration
vendor_redhat·2026-07-22·CVSS 5.9
CVE-2026-56444 [MEDIUM] CWE-772 unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration
unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration
A Denial of Service (DoS) flaw exists in Unbound under specific serve-expired and discard-timeout configurations. By sending crafted queries, a remote attacker can exhaust an internal counter, causing the server to drop new legitimate client queries and degrade resolution services.
Statement: This Low-impact flaw in Unbound can lead to a denial of service. While a remote attacker could exhaust the reply address counter with specially crafted queries, Red Hat products are not affected by default. The vulnerability requires specific non-default `serve-expired` and `discard-timeout` configurations, which are not present in standard Red Hat deployments.
Mitigation: To mitig
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56444 unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration [fedora-all]
bugzilla·2026-07-30·CVSS 5.9
CVE-2026-56444 [MEDIUM] CVE-2026-56444 unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration [fedora-all]
CVE-2026-56444 unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expire
Bugzilla
CVE-2026-56444 unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration
bugzilla·2026-07-22·CVSS 5.9
CVE-2026-56444 [MEDIUM] CVE-2026-56444 unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration
CVE-2026-56444 unbound: Unbound: Denial of Service due to incorrect client reply accounting with specific serve-expired configuration
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expired perform the correct decrement. Since the counter is never decremented in such scenario, it can reach the maximum limit and new clients for duplicate in-flight queries are silently dropped resulting in degradation of resolution service.
2026-07-22
Published