cbcvebase.

Nlnetlabs Unbound vulnerabilities

81 known vulnerabilities affecting nlnetlabs/unbound.

Total CVEs
81
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL12HIGH27MEDIUM33LOW9

Vulnerabilities

Page 4 of 5
CVE-2024-8508P4MEDIUMCVSS 5.3fixed in 1.21.12024-10-03
CVE-2024-8508 [MEDIUM] CWE-606 CVE-2024-8508: NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded perform
nvdosv
CVE-2026-42923P4MEDIUMCVSS 5.3≥ 1.19.1, < 1.25.12026-05-20
CVE-2026-42923 [MEDIUM] CWE-407 CVE-2026-42923: NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator wh NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of service during the attack. An adversary that controls a DNSSEC signed zon
nvd
CVE-2017-15105P4MEDIUMCVSS 5.3fixed in 1.6.82018-01-23
CVE-2017-15105 [MEDIUM] CWE-358 CVE-2017-15105: A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An imp A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
nvdosv
CVE-2025-11411P4MEDIUMCVSS 5.7≥ 0, < 1.13.1-1+deb11u7≥ 0, < 1.17.1-2+deb12u4+2 more2025-10-22
CVE-2025-11411 [MEDIUM] CVE-2025-11411: NLnet Labs Unbound up to and including version 1 NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation information for the zone. Usually these RRSets are used to update the resolver's knowledge of the zone's name servers. A malicious actor can exploit the possible pois
osv
CVE-2026-56416P4MEDIUMCVSS 4.8fixed in 1.25.22026-07-22
CVE-2026-56416 [MEDIUM] CWE-354 CVE-2026-56416: In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RD In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight to 'query_dname_tolower()' without checking that a second name is actuall
nvd
CVE-2024-43168P4MEDIUMCVSS 4.8≥ 0, < 1.13.1-1+deb11u3≥ 0, < 1.17.1-2+deb12u3+1 more2024-08-12
CVE-2024-43168 [MEDIUM] CVE-2024-43168: DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the e DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red Hat products. NLnet Labs has
osv
CVE-2026-77955P4MEDIUMCVSS 4.4≥ 1.13.2, < 1.26.12026-09-16
CVE-2026-77955 [MEDIUM] CWE-345 CVE-2026-77955: In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchrono
nvd
CVE-2011-1922P4MEDIUMCVSS 4.3v1.0.0v1.0.1+20 more2011-05-31
CVE-2011-1922 [MEDIUM] CWE-399 CVE-2011-1922: daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automat daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
nvdosv
CVE-2011-4528P4MEDIUMCVSS 5.0≥ 0, < 1.4.14-12011-12-20
CVE-2011-4528 [MEDIUM] CVE-2011-4528: Unbound before 1 Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of service (daemon crash) via a crafted response.
osv
CVE-2020-28935P4MEDIUMCVSS 5.5fixed in 1.13.02020-12-07
CVE-2020-28935 [MEDIUM] CWE-59 CVE-2020-28935: NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including vers NLnet Labs Unbound, up to and including version 1.12.0, and NLnet Labs NSD, up to and including version 4.3.3, contain a local vulnerability that would allow for a local symlink attack. When writing the PID file, Unbound and NSD create the file if it is not there, or open an existing file for writing. In case the file was already present, they would
nvdosv
CVE-2009-4008P4MEDIUMCVSS 5.0≤ 1.4.3v0.0+28 more2011-06-02
CVE-2009-4008 [MEDIUM] CWE-399 CVE-2009-4008: Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
nvdosv
CVE-2010-0969P4MEDIUMCVSS 5.0≤ 1.4.2v0.0+27 more2010-03-16
CVE-2010-0969 [MEDIUM] CWE-399 CVE-2010-0969: Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote att Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
nvdosv
CVE-2026-77860P4LOWCVSS 3.7≥ 1.20.0, < 1.26.12026-09-16
CVE-2026-77860 [LOW] CVE-2026-77860: In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A malicious actor can exploit this by controlling an authoritative zone with short TTL,
nvd
CVE-2026-41637P4LOWCVSS 3.7≥ 1.22.0, < 1.25.22026-07-22
CVE-2026-41637 [LOW] CWE-772 CVE-2026-41637: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queri In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already in-flight resolution queries. This results in degradation of resolution service for new clients for already in-flight queries. A malicio
nvd
CVE-2026-42955P4LOWCVSS 3.7≥ 1.16.2, < 1.25.22026-07-22
CVE-2026-42955 [LOW] CVE-2026-42955: In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40 In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (gho
nvd
CVE-2026-46582P4LOWCVSS 3.7≥ 1.6.0, < 1.25.22026-07-22
CVE-2026-46582 [LOW] CWE-358 CVE-2026-46582: In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piec In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread tha
nvd
CVE-2026-50243P4LOWCVSS 3.7≥ 1.6.2, < 1.25.22026-07-22
CVE-2026-50243 [LOW] CWE-348 CVE-2026-50243: In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of the upstream answer and can instead rewrite a BOGUS A/AAAA answer to point to
nvd
CVE-2026-54478P4LOWCVSS 3.7≥ 1.18.0, < 1.25.22026-07-22
CVE-2026-54478 [LOW] CWE-290 CVE-2026-54478: In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-p In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie obtained through a given proxy node therefore validates for every PROXYv2-dec
nvd
CVE-2026-44687P4LOWCVSS 3.7≥ 1.13.2, < 1.25.22026-07-22
CVE-2026-44687 [LOW] CWE-193 CVE-2026-44687: In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is bel In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the parent. This is caused by an off-by-one error in 'harden-below-nxdomain' logic; enabled by default. It effectively bypasses
nvd
CVE-2026-55708P4LOWCVSS 3.1≥ 1.6.0, < 1.25.22026-07-22
CVE-2026-55708 [LOW] CWE-1188 CVE-2026-55708: In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones
nvd
Nlnetlabs Unbound vulnerabilities | cvebase