Nlnet Labs Unbound vulnerabilities
50 known vulnerabilities affecting nlnet_labs/unbound.
Total CVEs
50
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH15MEDIUM25LOW6
Vulnerabilities
Page 3 of 3
CVE-2025-11411P4MEDIUMCVSS 5.7fixed in 1.25.12025-10-22
CVE-2025-11411 [MEDIUM] CWE-349 CVE-2025-11411: NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attack
NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's n
nvd
CVE-2026-56416P4MEDIUMCVSS 4.8fixed in 1.25.22026-07-22
CVE-2026-56416 [MEDIUM] CWE-354 CVE-2026-56416: In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RD
In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actuall
nvd
CVE-2026-77955P4MEDIUMCVSS 4.4≥ 1.13.2, < 1.26.12026-09-16
CVE-2026-77955 [MEDIUM] CWE-345 CVE-2026-77955: In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchrono
nvd
CVE-2020-28935P4MEDIUMCVSS 5.5≤ 1.12.02020-12-07
CVE-2020-28935 [MEDIUM] CWE-59 CVE-2020-28935: NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including vers
NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an existing file for writing. In case the file was already present, they would
nvd
CVE-2026-41637P4LOWCVSS 3.7≥ 1.22.0, < 1.25.22026-07-22
CVE-2026-41637 [LOW] CWE-772 CVE-2026-41637: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queri
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already in-flight resolution queries. This results in degradation of resolution service for new clients for already in-flight queries. A malicio
nvd
CVE-2026-46582P4LOWCVSS 3.7≥ 1.6.0, < 1.25.22026-07-22
CVE-2026-46582 [LOW] CWE-358 CVE-2026-46582: In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piec
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread tha
nvd
CVE-2026-50243P4LOWCVSS 3.7≥ 1.6.2, < 1.25.22026-07-22
CVE-2026-50243 [LOW] CWE-348 CVE-2026-50243: In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip'
In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of the upstream answer and can instead rewrite a BOGUS A/AAAA answer to point to
nvd
CVE-2026-54478P4LOWCVSS 3.7≥ 1.18.0, < 1.25.22026-07-22
CVE-2026-54478 [LOW] CWE-290 CVE-2026-54478: In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-p
In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie obtained through a given proxy node therefore validates for every PROXYv2-dec
nvd
CVE-2026-44687P4LOWCVSS 3.7≥ 1.13.2, < 1.25.22026-07-22
CVE-2026-44687 [LOW] CWE-193 CVE-2026-44687: In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is bel
In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the parent. This is caused by an off-by-one error in 'harden-below-nxdomain' logic; enabled by default. It effectively bypasses
nvd
CVE-2026-55708P4LOWCVSS 3.1≥ 1.6.0, < 1.25.22026-07-22
CVE-2026-55708 [LOW] CWE-1188 CVE-2026-55708: In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas'
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones
nvd
← Previous3 / 3