VYPR

Unbound

by Nlnetlabs

Source repositories

CVEs (80)

  • CVE-2026-78227MedSep 16, 2026
    risk 0.35cvss 6.5epss 0.00

    NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2's retransmission buffer keeps a shallow pointer…

  • CVE-2026-50248MedJul 22, 2026
    risk 0.35cvss 6.5epss 0.00

    In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG…

  • CVE-2017-15105MedJan 23, 2018
    risk 0.35cvss 5.3epss 0.03

    A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.

  • CVE-2026-82720MedSep 16, 2026
    risk 0.31cvss 5.9epss 0.00

    NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole…

  • CVE-2026-56444MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged…

  • CVE-2026-55991MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is…

  • CVE-2026-55990MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that…

  • CVE-2026-55717MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: redirect' /'response-ip-data: CNAME ' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain…

  • CVE-2026-52863MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.25.0 up to and including 1.25.1, a fix that makes the 'respip' and 'dns64' modules work together, creates a shallow copy of the view name in effect that could lead to memory corruption if the owner of the original view name is jostled out when Unbound is…

  • CVE-2026-50046MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh…

  • CVE-2026-44621MedJul 22, 2026
    risk 0.31cvss 5.9epss 0.00

    With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function…

  • CVE-2026-44608MedMay 20, 2026
    risk 0.31cvss 5.9epss 0.00

    NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual…

  • CVE-2024-43168MedAug 12, 2024
    risk 0.31cvss 4.8epss 0.00

    DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made a claim that there is a security risk within Red…

  • CVE-2026-44390MedMay 20, 2026
    risk 0.28cvss 5.3epss 0.01

    NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root…

  • CVE-2024-8508MedOct 3, 2024
    risk 0.28cvss 5.3epss 0.01

    NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend a considerable time applying…

  • CVE-2026-85501MedSep 16, 2026
    risk 0.27cvss 5.3epss 0.00

    Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including…

  • CVE-2026-80225MedSep 16, 2026
    risk 0.27cvss 5.3epss 0.00

    In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT…

  • CVE-2026-50251MedJul 22, 2026
    risk 0.27cvss 5.3epss 0.00

    In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving…

  • CVE-2026-50045MedJul 22, 2026
    risk 0.27cvss 5.3epss 0.00

    In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security…

  • CVE-2026-42923MedMay 20, 2026
    risk 0.27cvss 5.3epss 0.00

    NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the DNSSEC validator where the code path to consult the negative cache for DS records does not take into account the limit on NSEC3 hash calculations introduced in 1.19.1. This leads to degradation of…