VYPR

Unbound

by Nlnetlabs

Source repositories

CVEs (71)

  • CVE-2026-55991MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is…

  • CVE-2026-55990MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that…

  • CVE-2026-55717MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: redirect' /'response-ip-data: CNAME ' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain…

  • CVE-2026-52863MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is…

  • CVE-2026-50046MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh…

  • CVE-2026-44621MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function…

  • CVE-2026-44608MedMay 20, 2026
    risk 0.31cvss 5.9epss 0.00

    NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual…

  • CVE-2024-43168MedAug 12, 2024
    risk 0.31cvss 4.8epss 0.00

    DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red…

  • CVE-2026-44390MedMay 20, 2026
    risk 0.28cvss 5.3epss 0.01

    NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root…

  • CVE-2024-8508MedOct 3, 2024
    risk 0.28cvss 5.3epss 0.01

    NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying…

  • CVE-2026-50251MedJul 22, 2026
    risk 0.27cvss 5.3epss 0.00

    In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving…

  • CVE-2026-50045MedJul 22, 2026
    risk 0.27cvss 5.3epss 0.00

    In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security…

  • CVE-2026-42923MedMay 20, 2026
    risk 0.27cvss 5.3epss 0.00

    NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of…

  • CVE-2026-42534MedMay 20, 2026
    risk 0.27cvss 5.3epss 0.01

    NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as…

  • CVE-2026-32792MedMay 20, 2026
    risk 0.27cvss 5.3epss 0.00

    NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A…

  • CVE-2026-56416MedJul 22, 2026
    risk 0.24cvss 4.8epss 0.00

    In NLnet Labs Unbound up to and including version 1.25.1, when the validator builds the canonical RDATA form for an RRSIG-covered PX/RP/MINFO/SOA RRset, it computes the address of the second embedded domain name as 'datstart + dname_valid(datstart, ...)' and passes it straight…

  • CVE-2024-43167LowAug 12, 2024
    risk 0.18cvss 2.8epss 0.00

    DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red…

  • CVE-2026-54478LowJul 22, 2026
    risk 0.17cvss 3.7epss 0.00

    In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie…

  • CVE-2026-50243LowJul 22, 2026
    risk 0.17cvss 3.7epss 0.00

    In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of…

  • CVE-2026-46582LowJul 22, 2026
    risk 0.17cvss 3.7epss 0.00

    In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation.…