cbcvebase.

Nlnet Labs Unbound vulnerabilities

50 known vulnerabilities affecting nlnet_labs/unbound.

Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH15MEDIUM25LOW6

Vulnerabilities

Page 1 of 3
CVE-2026-81642P2CRITICALCVSS 9.8fixed in 1.26.12026-09-16
CVE-2026-81642 [CRITICAL] CWE-122 CVE-2026-81642: In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker control
nvd
CVE-2026-82717P2CRITICALCVSS 9.8fixed in 1.26.12026-09-16
CVE-2026-82717 [CRITICAL] CWE-122 CVE-2026-82717: In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressivel In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Co
nvd
CVE-2026-33278P2CRITICALCVSS 9.8≥ 1.19.1, < 1.25.12026-05-20
CVE-2026-33278 [CRITICAL] CWE-416 CVE-2026-33278: NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC valid NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone
nvd
CVE-2026-50252P3CRITICALCVSS 9.3≥ 1.4.22, < 1.25.22026-07-22
CVE-2026-50252 [CRITICAL] CWE-349 CVE-2026-50252: In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing po
nvd
CVE-2026-81634P3HIGHCVSS 7.5fixed in 1.26.12026-09-16
CVE-2026-81634 [HIGH] CWE-122 CVE-2026-81634: In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response t
nvd
CVE-2026-42944P3HIGHCVSS 7.5≥ 1.14.0, < 1.25.12026-05-20
CVE-2026-42944 [HIGH] CWE-197 CVE-2026-42944: NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in hea NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversa
nvd
CVE-2026-32665P3HIGHCVSS 7.5≥ 1.22.0, < 1.25.22026-07-22
CVE-2026-32665 [HIGH] CWE-1284 CVE-2026-32665: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enab In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has been received from the initial s
nvd
CVE-2025-5994P3HIGHCVSS 8.7≥ 1.6.2, < 1.23.02025-07-16
CVE-2025-5994 [HIGH] CWE-349 CVE-2025-5994: A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in cachin A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-clie
nvd
CVE-2026-85501P3HIGHCVSS 7.5fixed in 1.26.12026-09-16
CVE-2026-85501 [HIGH] CWE-770 CVE-2026-85501: Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo
nvd
CVE-2026-44690P3HIGHCVSS 7.5≥ 1.7.0, < 1.25.22026-07-22
CVE-2026-44690 [HIGH] CWE-345 CVE-2026-44690: In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malici
nvd
CVE-2026-40622P3HIGHCVSS 7.5≥ 1.16.2, < 1.25.22026-05-20
CVE-2026-40622 [HIGH] CWE-346 CVE-2026-40622: NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domai NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A singl
nvd
CVE-2026-41292P3HIGHCVSS 7.5fixed in 1.25.12026-05-20
CVE-2026-41292 [HIGH] CWE-407 CVE-2026-41292: NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service atta NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can res
nvd
CVE-2026-80225P3HIGHCVSS 7.5fixed in 1.26.12026-09-16
CVE-2026-80225 [HIGH] CWE-770 CVE-2026-80225: In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present i In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its
nvd
CVE-2024-1931P3HIGHCVSS 7.5≥ 1.18.0, < 1.19.22024-03-07
CVE-2024-1931 [HIGH] CWE-835 CVE-2024-1931: NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that ca NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher than the client's advertised buffer size. Before removing all the EDE records
nvd
CVE-2026-42959P3HIGHCVSS 7.5fixed in 1.25.12026-05-20
CVE-2026-42959 [HIGH] CWE-824 CVE-2026-42959: NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the D NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could inc
nvd
CVE-2026-55973P3HIGHCVSS 7.5≥ 1.23.0, < 1.25.22026-07-22
CVE-2026-55973 [HIGH] CWE-20 CVE-2026-55973: In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent doma
nvd
CVE-2026-40691P3HIGHCVSS 7.5≥ 1.9.0, < 1.25.22026-07-22
CVE-2026-40691 [HIGH] CWE-122 CVE-2026-40691: In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is shifted forward by 48 bytes inside a b
nvd
CVE-2026-78227P3MEDIUMCVSS 6.5≥ 1.22.0, < 1.26.12026-09-16
CVE-2026-78227 [MEDIUM] CWE-416 CVE-2026-78227: NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compil NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retransmission buffer keeps a shallow pointer into the output buffer for as long as a STREAM frame may be resent. On a cl
nvd
CVE-2022-3204P3HIGHCVSS 7.5≥ unspecified, ≤ 1.16.22022-09-26
CVE-2022-3204 [HIGH] CWE-400 CVE-2022-3204: A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered i A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers.
nvd
CVE-2024-33655P3HIGHCVSS 7.5≥ 1.20.0, < 1.26.12024-06-06
CVE-2024-33655 [HIGH] CWE-400 CVE-2024-33655: The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resou The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.
nvd
Nlnet Labs Unbound vulnerabilities | cvebase