VYPR
Vypr IntelligenceAI-generatedJul 23, 2026· 23 CVEs

Nlnetlabs Unbound: 23 Vulnerabilities Disclosed Together in DNSSEC, DoQ, and RPZ Handling

Nlnetlabs patched 23 vulnerabilities in Unbound DNS resolver disclosed on July 23, 2026, affecting versions 1.10.0 through 1.25.1.

Key findings

  • 23 vulnerabilities disclosed simultaneously for Nlnetlabs Unbound on July 23, 2026.
  • Issues span DNSSEC, DoQ, RPZ, and core resolver logic, impacting versions 1.10.0 to 1.25.1.
  • Vulnerabilities include denial-of-service, cache poisoning, and improper data handling.
  • Nlnetlabs released version 1.25.2 to address all disclosed vulnerabilities.
  • Users are urged to update to Unbound 1.25.2 to mitigate security risks.

On July 23, 2026, Nlnetlabs released a significant security update for its Unbound DNS resolver, addressing a batch of 23 vulnerabilities. These vulnerabilities, disclosed simultaneously, span various aspects of Unbound's functionality, including DNSSEC processing, DNS-over-QUIC (DoQ) handling, and response policy zones (RPZ). The wide range of issues underscores the complexity of maintaining secure DNS infrastructure and the importance of timely patching.

Several vulnerabilities relate to Unbound's DNSSEC validation and caching mechanisms. CVE-2026-44690 and CVE-2026-16582 highlight flaws in aggressive NSEC processing and wildcard record handling, respectively, which could lead to cache poisoning and the acceptance of DNSSEC-invalid data. Additionally, CVE-2026-56416 points to an issue in building canonical RDATA forms for certain record types, potentially impacting DNSSEC validation integrity.

The batch also includes multiple vulnerabilities associated with DNS-over-QUIC (DoQ). CVE-2026-55991 and CVE-2026-14586 describe conditions where malformed DoQ connections or high concurrency could lead to assertion failures or denial-of-service conditions by terminating the Unbound process. CVE-2026-17 and CVE-2026-41637 address improper handling of stream sizes and client-terminated queries in DoQ, potentially leading to resource exhaustion and degraded service.

Response Policy Zones (RPZ) and related features are also affected. CVE-2026-50243 details how the 'respip' module might rewrite responses without checking upstream answer security, while CVE-2026-55717 and CVE-2026-56444 describe issues with 'serve-expired' functionality and client timeouts that could lead to daemon crashes or incorrect handling of aged replies. CVE-2026-50045 and CVE-2026-42955 touch upon upstream packet amplification and extending ghost domain windows, respectively, impacting Unbound's ability to control resource usage and mitigate certain cache-based attacks.

Other vulnerabilities include issues with proxy protocol handling (CVE-2026-54478), memory corruption in module interactions (CVE-2026-52863), improper handling of TLS server names in DoT (CVE-2026-50046), and a missing function call in libunbound applications (CVE-2026-44621). Furthermore, CVE-2026-50252 and CVE-2026-50251 highlight potential weaknesses in UDP source port randomization and the handling of unwanted replies with 'unwanted-reply-threshold' enabled. The unbound-control command-line utility is also affected by CVE-2026-55708, which involves improper creation of local zone trees. Finally, CVE-2026-55990 and CVE-2026-55973 address potential memory corruption related to dnscrypt configurations and improper handling of EDNS Report-Channel options.

All 23 vulnerabilities affect Unbound versions from 1.10.0 up to and including 1.25.1. Nlnetlabs has released version 1.25.2 to address these issues. Users are strongly advised to update to the latest version to mitigate these security risks. The simultaneous disclosure of such a large batch indicates a coordinated effort to address a wide array of potential security weaknesses within the Unbound DNS resolver.

Key Findings:

  • A batch of 23 vulnerabilities was disclosed for Nlnetlabs Unbound on July 23, 2026.
  • Multiple issues affect DNSSEC validation, DNS-over-QUIC (DoQ), and Response Policy Zones (RPZ).
  • Vulnerabilities range from denial-of-service conditions to potential cache poisoning.
  • All reported issues are fixed in Unbound version 1.25.2.
  • Versions 1.10.0 through 1.25.1 are affected by these vulnerabilities.
  • Several CVEs relate to improper handling of DNSSEC, DoQ, and RPZ configurations.
AI-written article. Grounded in 23 CVE records listed below.