cbcvebase.

Nlnetlabs Unbound vulnerabilities

81 known vulnerabilities affecting nlnetlabs/unbound.

Total CVEs
81
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH27MEDIUM33LOW9

Vulnerabilities

Page 1 of 5
CVE-2023-50387P3HIGHCVSS 7.5fixed in 1.19.12024-02-14
CVE-2023-50387 [HIGH] CWE-770 CVE-2023-50387: Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow r Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an al
nvdosv
CVE-2023-50868P3HIGHCVSS 7.5≥ 0, < 1.13.1-1+deb11u2≥ 0, < 1.17.1-2+deb12u2+1 more2024-02-14
CVE-2023-50868 [HIGH] CVE-2023-50868: The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of ser The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that a
osv
CVE-2026-81642P2CRITICALCVSS 9.8fixed in 1.26.12026-09-16
CVE-2026-81642 [CRITICAL] CWE-122 CVE-2026-81642: In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker control
nvd
CVE-2026-82717P2CRITICALCVSS 9.8fixed in 1.26.12026-09-16
CVE-2026-82717 [CRITICAL] CWE-122 CVE-2026-82717: In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressivel In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Co
nvd
CVE-2026-33278P2CRITICALCVSS 9.8≥ 1.19.1, < 1.25.12026-05-20
CVE-2026-33278 [CRITICAL] CWE-416 CVE-2026-33278: NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC valid NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone
nvd
CVE-2026-42960P3CRITICALCVSS 10.0fixed in 1.25.12026-05-20
CVE-2026-42960 [CRITICAL] CVE-2026-42960: NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous rec NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack
nvd
CVE-2019-25034P3CRITICALCVSS 9.8fixed in 1.9.52021-04-27
CVE-2019-25034 [CRITICAL] CWE-190 CVE-2019-25034: Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an ou Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25042P3CRITICALCVSS 9.8fixed in 1.9.52021-04-27
CVE-2019-25042 [CRITICAL] CWE-787 CVE-2019-25042: Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The ve Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25035P3CRITICALCVSS 9.8fixed in 1.9.52021-04-27
CVE-2019-25035 [CRITICAL] CWE-787 CVE-2019-25035: Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor dispute Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25038P3CRITICALCVSS 9.8fixed in 1.9.52021-04-27
CVE-2019-25038 [CRITICAL] CWE-190 CVE-2019-25038: Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25039P3CRITICALCVSS 9.8fixed in 1.9.52021-04-27
CVE-2019-25039 [CRITICAL] CWE-190 CVE-2019-25039: Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25032P3CRITICALCVSS 9.8fixed in 1.9.52021-04-27
CVE-2019-25032 [CRITICAL] CWE-190 CVE-2019-25032: Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25033P3CRITICALCVSS 9.8fixed in 1.9.52021-04-27
CVE-2019-25033 [CRITICAL] CWE-190 CVE-2019-25033: Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NO Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2026-50252P3CRITICALCVSS 9.3≥ 1.4.22, < 1.25.22026-07-22
CVE-2026-50252 [CRITICAL] CWE-349 CVE-2026-50252: In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing po
nvd
CVE-2026-81634P3HIGHCVSS 7.5fixed in 1.26.12026-09-16
CVE-2026-81634 [HIGH] CWE-122 CVE-2026-81634: In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response t
nvd
CVE-2026-42944P3HIGHCVSS 7.5≥ 1.14.0, < 1.25.12026-05-20
CVE-2026-42944 [HIGH] CWE-197 CVE-2026-42944: NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in hea NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when encoding multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options in the reply packet. The relevant options ('nsid', 'answer-cookie', 'pad-responses' (default)) need to be enabled for the vulnerability to be exploited. An adversa
nvd
CVE-2026-32665P3HIGHCVSS 7.5≥ 1.22.0, < 1.25.22026-07-22
CVE-2026-32665 [HIGH] CWE-1284 CVE-2026-32665: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enab In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has been received from the initial s
nvd
CVE-2019-18934P3HIGHCVSS 7.3≥ 1.6.4, ≤ 1.9.42019-11-19
CVE-2019-18934 [HIGH] CWE-78 CVE-2019-18934: Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code ex Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.
nvdosv
CVE-2025-5994P3HIGHCVSS 8.7≥ 0, < 1.13.1-1+deb11u5≥ 0, < 1.17.1-2+deb12u3+1 more2025-07-16
CVE-2025-5994 [HIGH] CVE-2025-5994: A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS) A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name serv
osv
CVE-2026-85501P3HIGHCVSS 7.5fixed in 1.26.12026-09-16
CVE-2026-85501 [HIGH] CWE-770 CVE-2026-85501: Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where the triple(Zone, Algo
nvd
Nlnetlabs Unbound vulnerabilities | cvebase