Nlnet Labs Unbound vulnerabilities
50 known vulnerabilities affecting nlnet_labs/unbound.
Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH15MEDIUM25LOW6
Vulnerabilities
Page 2 of 3
CVE-2026-50248P3MEDIUMCVSS 6.5≥ 1.7.0, < 1.25.22026-07-22
CVE-2026-50248 [MEDIUM] CWE-345 CVE-2026-50248: In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured prima
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the r
nvd
CVE-2022-30699P3MEDIUMCVSS 6.5≥ unspecified, ≤ 1.16.12022-08-01
CVE-2022-30699 [MEDIUM] CWE-613 CVE-2022-30699: NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation
nvd
CVE-2022-30698P4MEDIUMCVSS 6.5≥ unspecified, ≤ 1.16.12022-08-01
CVE-2022-30698 [MEDIUM] CWE-613 CVE-2022-30698: NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost d
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation information for the subdomain that updates Unbound's delegation cache. Th
nvd
CVE-2026-52863P3MEDIUMCVSS 5.9≥ 1.25.0, < 1.25.22026-07-22
CVE-2026-52863 [MEDIUM] CWE-416 CVE-2026-52863: In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' m
In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. Unbound needs to be configured with one of 'respip'/'rpz
nvd
CVE-2026-55990P4MEDIUMCVSS 5.9≥ 1.7.0, < 1.25.22026-07-22
CVE-2026-55990 [MEDIUM] CWE-457 CVE-2026-55990: In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnsc
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate ove
nvd
CVE-2026-55991P4MEDIUMCVSS 5.9≥ 1.22.0, < 1.25.22026-07-22
CVE-2026-55991 [MEDIUM] CWE-195 CVE-2026-55991: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is caused by an erroneous error value passed to libngtcp2. When 'ngtcp2_conn_
nvd
CVE-2026-82720P4MEDIUMCVSS 5.9≥ 1.12.0, < 1.26.12026-09-16
CVE-2026-82720 [MEDIUM] CWE-416 CVE-2026-82720: NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compile
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the sam
nvd
CVE-2026-56444P4MEDIUMCVSS 5.9≥ 1.20.0, < 1.25.22026-07-22
CVE-2026-56444 [MEDIUM] CWE-772 CVE-2026-56444: In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expi
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of rep
nvd
CVE-2026-14586P4MEDIUMCVSS 5.9≥ 1.22.0, < 1.25.22026-07-22
CVE-2026-14586 [MEDIUM] CWE-617 CVE-2026-14586: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high co
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use
nvd
CVE-2026-44621P4MEDIUMCVSS 5.9fixed in 1.25.22026-07-22
CVE-2026-44621 [MEDIUM] CWE-754 CVE-2026-44621: With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and config
With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using
nvd
CVE-2026-42534P4MEDIUMCVSS 5.3fixed in 1.25.12026-05-20
CVE-2026-42534 [MEDIUM] CWE-440 CVE-2026-42534: NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that c
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for replacement with new queries. An adversa
nvd
CVE-2026-50046P4MEDIUMCVSS 5.9≥ 1.15.0, < 1.25.22026-07-22
CVE-2026-50046 [MEDIUM] CWE-416 CVE-2026-50046: In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind
nvd
CVE-2026-55717P4MEDIUMCVSS 5.9≥ 1.10.0, < 1.25.22026-07-22
CVE-2026-55717 [MEDIUM] CWE-476 CVE-2026-55717: In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together w
In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: redirect' /'response-ip-data: CNAME ' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chas
nvd
CVE-2026-44608P4MEDIUMCVSS 5.9≥ 1.14.0, < 1.25.12026-05-20
CVE-2026-44608 [MEDIUM] CWE-413 CVE-2026-44608: NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerabili
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met
nvd
CVE-2026-50251P4MEDIUMCVSS 5.3fixed in 1.25.22026-07-22
CVE-2026-50251 [MEDIUM] CWE-184 CVE-2026-50251: In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled
In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original sour
nvd
CVE-2026-32792P4MEDIUMCVSS 5.3≥ 1.6.2, < 1.25.12026-05-20
CVE-2026-32792 [MEDIUM] CWE-125 CVE-2026-32792: NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability wh
NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the vulnerability with a single bad DNSCrypt query
nvd
CVE-2026-50045P4MEDIUMCVSS 5.3≥ 1.22.0, < 1.25.22026-07-22
CVE-2026-50045 [MEDIUM] CWE-406 CVE-2026-50045: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested n
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.
nvd
CVE-2024-8508P4MEDIUMCVSS 5.3fixed in 1.25.12024-10-03
CVE-2024-8508 [MEDIUM] CWE-606 CVE-2024-8508: NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies
NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded perform
nvd
CVE-2026-42923P4MEDIUMCVSS 5.3fixed in 1.25.12026-05-20
CVE-2026-42923 [MEDIUM] CWE-407 CVE-2026-42923: NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator wh
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the attack. An adversary that controls a DNSSEC signed zon
nvd
CVE-2017-15105P4MEDIUMCVSS 5.3vbefore 1.6.82018-01-23
CVE-2017-15105 [MEDIUM] CWE-358 CVE-2017-15105: A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An imp
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
nvd