cbcvebase.

Nlnetlabs Unbound vulnerabilities

81 known vulnerabilities affecting nlnetlabs/unbound.

Total CVEs
81
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH27MEDIUM33LOW9

Vulnerabilities

Page 2 of 5
CVE-2026-44690P3HIGHCVSS 7.5≥ 1.7.0, < 1.25.22026-07-22
CVE-2026-44690 [HIGH] CWE-345 CVE-2026-44690: In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malici
nvd
CVE-2026-40622P3HIGHCVSS 7.5≥ 1.16.2, < 1.25.12026-05-20
CVE-2026-40622 [HIGH] CWE-346 CVE-2026-40622: NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domai NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A singl
nvd
CVE-2026-41292P3HIGHCVSS 7.5fixed in 1.25.12026-05-20
CVE-2026-41292 [HIGH] CWE-407 CVE-2026-41292: NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service atta NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can res
nvd
CVE-2026-80225P3HIGHCVSS 7.5fixed in 1.26.12026-09-16
CVE-2026-80225 [HIGH] CWE-770 CVE-2026-80225: In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present i In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its
nvd
CVE-2019-16866P3HIGHCVSS 7.5fixed in 1.9.42019-10-03
CVE-2019-16866 [HIGH] CWE-755 CVE-2019-16866: Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
nvdosv
CVE-2024-1931P3HIGHCVSS 7.5≥ 1.18.0, < 1.19.22024-03-07
CVE-2024-1931 [HIGH] CWE-835 CVE-2024-1931: NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that ca NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher than the client's advertised buffer size. Before removing all the EDE records
nvdosv
CVE-2026-42959P3HIGHCVSS 7.5fixed in 1.25.12026-05-20
CVE-2026-42959 [HIGH] CWE-824 CVE-2026-42959: NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the D NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for validation, the code uses the wrong counter to calculate write offsets for ADDITIONAL section rrsets. DNAME duplication could inc
nvd
CVE-2026-55973P3HIGHCVSS 7.5≥ 1.23.0, < 1.25.22026-07-22
CVE-2026-55973 [HIGH] CWE-20 CVE-2026-55973: In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the In NLnet Labs Unbound 1.23.0 up to and including 1.25.1, when 'dns-error-reporting: yes' is set, the EDNS Report-Channel option (code 18) from the last upstream response is read and uses the option's length as the length of the agent domain. When a domain name check is performed on the agent domain, the returned lenght is not used and if the agent doma
nvd
CVE-2026-40691P3HIGHCVSS 7.5≥ 1.9.0, < 1.25.22026-07-22
CVE-2026-40691 [HIGH] CWE-122 CVE-2026-40691: In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine In Unbound 1.9.0 up to and including 1.25.1, when a DNSCrypt query is received over TCP, the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. The size clamp that protects the UDP path is not applied on the TCP path, so a reply larger than 65504 bytes is shifted forward by 48 bytes inside a b
nvd
CVE-2020-12662P3HIGHCVSS 7.5fixed in 1.10.12020-05-19
CVE-2020-12662 [HIGH] CWE-400 CVE-2020-12662: Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
nvdosv
CVE-2026-78227P3MEDIUMCVSS 6.5≥ 1.22.0, < 1.26.12026-09-16
CVE-2026-78227 [MEDIUM] CWE-416 CVE-2026-78227: NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compil NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retransmission buffer keeps a shallow pointer into the output buffer for as long as a STREAM frame may be resent. On a cl
nvd
CVE-2019-25041P3HIGHCVSS 7.5fixed in 1.9.52021-04-27
CVE-2019-25041 [HIGH] CWE-617 CVE-2019-25041: Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2019-25040P3HIGHCVSS 7.5fixed in 1.9.52021-04-27
CVE-2019-25040 [HIGH] CWE-835 CVE-2019-25040: Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vend Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2022-3204P3HIGHCVSS 7.5≤ 1.16.22022-09-26
CVE-2022-3204 [HIGH] CWE-400 CVE-2022-3204: A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered i A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers.
nvdosv
CVE-2020-12663P3HIGHCVSS 7.5fixed in 1.10.12020-05-19
CVE-2020-12663 [HIGH] CWE-835 CVE-2020-12663: Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
nvdosv
CVE-2019-25036P3HIGHCVSS 7.5fixed in 1.9.52021-04-27
CVE-2019-25036 [HIGH] CWE-617 CVE-2019-25036: Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The ven Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2024-33655P3HIGHCVSS 7.5≥ 0, < 1.13.1-1+deb11u5≥ 0, < 1.17.1-2+deb12u3+1 more2024-06-06
CVE-2024-33655 [HIGH] CVE-2024-33655: The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to b The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb"
osv
CVE-2019-25037P3HIGHCVSS 7.5fixed in 1.9.52021-04-27
CVE-2019-25037 [HIGH] CWE-617 CVE-2019-25037: Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an inva Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
nvdosv
CVE-2020-10772P3HIGHCVSS 7.5v1.6.6-5vunbound-1.6.6-5.el7_82020-11-27
CVE-2020-10772 [HIGH] CWE-406 CVE-2020-10772: An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned e
nvd
CVE-2026-50248P3MEDIUMCVSS 6.5≥ 1.7.0, < 1.25.22026-07-22
CVE-2026-50248 [MEDIUM] CWE-345 CVE-2026-50248: In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured prima In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the r
nvd
Nlnetlabs Unbound vulnerabilities | cvebase