CVE-2026-77860
published 2026-09-16CVE-2026-77860: In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit'…
PriorityP419low3.7CVSS 3.1
AVNACHPRNUINSUCNINAL
EPSS
0.30%
20.9th percentile
In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A malicious actor can exploit this by controlling an authoritative zone with short TTL, so cached entries expire quickly. Each 'slow' query, one the attacker's authoritative never answers, is followed by one query for an expired cached name, which is answered immediately via the 'serve-expired' path and decrements the counter twice. This second query was named 'pump'. By alternating slow queries and pumps, the attacker keeps the per-client counter at or below the configured 'wait-limit' indefinitely, and can hold an arbitrary number of pending queries from a single source IP, up to the global mesh quota (num-queries-per-thread); eventually bypassing one of the counter measures introduced for DNSBomb (CVE-2024-33655). This vulnerability is present on the 'serve-expired' code path.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnetlabs | unbound | >= 1.20.0 < 1.26.1 | 1.26.1 |
| openshift | ose-rhel-coreos-8 | — | — |
| openshift | ose-rhel-coreos-9 | — | — |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing on
ghsa_unreviewed·2026-09-16·CVSS 7.5
CVE-2026-77860 [HIGH] CWE-675 In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing on
In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A malicious actor can exploit this by controlling an authoritative zone with short TTL, so cached entries expire quickly. Each 'slow' query, one the attacker's authoritative never answers, is followed by one query for an expired cached name, which is answered immediately via the 'serve-expired' path and decrements the counter twice. This second query was named 'pump'. By alternating slow queries and pumps, the attacker keeps the per-client counter at or below the configured 'wait-limit' indefinitely, and can hold an ar
Red Hat
unbound: Unbound: Denial of Service via 'serve-expired' code path bypass
vendor_redhat·2026-09-16·CVSS 3.7
CVE-2026-77860 [LOW] CWE-911 unbound: Unbound: Denial of Service via 'serve-expired' code path bypass
unbound: Unbound: Denial of Service via 'serve-expired' code path bypass
A flaw was found in Unbound. A remote attacker can exploit a vulnerability in the 'serve-expired' code path by sending specially crafted DNS queries. This manipulation causes a double decrement of a security counter, effectively bypassing a protection mechanism designed to limit pending queries. Consequently, an attacker can hold an arbitrary number of pending queries from a single source, leading to a Denial of Service (DoS) condition.
Package: openshift/ose-rhel-coreos-8 (Red Hat OpenShift Container Platform 4) - Fix deferred
Package: openshift/ose-rhel-coreos-9 (Red Hat OpenShift Container Platform 4) - Fix deferred
No detection rules found.
No public exploits indexed.
Hackernews
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
blogs_hackernews·2026-09-17·CVSS 9.8
CVE-2026-81642 [CRITICAL] Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws. One of the eight, CVE-2026-82717 , is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code
Bugzilla
CVE-2026-77860 unbound: Unbound: Denial of Service via 'serve-expired' code path bypass [fedora-all]
bugzilla·2026-09-21·CVSS 7.5
CVE-2026-77860 [HIGH] CVE-2026-77860 unbound: Unbound: Denial of Service via 'serve-expired' code path bypass [fedora-all]
CVE-2026-77860 unbound: Unbound: Denial of Service via 'serve-expired' code path bypass [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A malicious actor can exploit this by controlling an authoritative zone with short TTL, so cached entries expire quickly. Each 'slow' query, one the attacker's authoritative never answers, is follo
Bugzilla
CVE-2026-77860 unbound: Unbound: Denial of Service via 'serve-expired' code path bypass
bugzilla·2026-09-16·CVSS 7.5
CVE-2026-77860 [HIGH] CVE-2026-77860 unbound: Unbound: Denial of Service via 'serve-expired' code path bypass
CVE-2026-77860 unbound: Unbound: Denial of Service via 'serve-expired' code path bypass
In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A malicious actor can exploit this by controlling an authoritative zone with short TTL, so cached entries expire quickly. Each 'slow' query, one the attacker's authoritative never answers, is followed by one query for an expired cached name, which is answered immediately via the 'serve-expired' path and decrements the counter twice. This second query was named 'pump'. By alternating slow queries and pumps, the attacker keeps the pe
2026-09-16
Published