CVE-2025-5994
- EPSS 0.04%
- Published 16.07.2025 14:38:22
- Last modified 17.07.2025 21:15:50
A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured ...
CVE-2024-8508
- EPSS 0.83%
- Published 03.10.2024 17:15:15
- Last modified 17.12.2024 19:28:03
NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend...
CVE-2024-1931
- EPSS 6.75%
- Published 07.03.2024 10:15:07
- Last modified 17.12.2024 16:56:50
NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from ...
CVE-2023-50387
- EPSS 42.22%
- Published 14.02.2024 16:15:45
- Last modified 12.05.2025 15:15:56
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that,...
CVE-2022-3204
- EPSS 0.29%
- Published 26.09.2022 14:15:11
- Last modified 05.05.2025 16:15:19
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameserv...
CVE-2022-30699
- EPSS 0.16%
- Published 01.08.2022 15:15:09
- Last modified 21.11.2024 07:03:11
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation ...
CVE-2022-30698
- EPSS 0.16%
- Published 01.08.2022 15:15:09
- Last modified 21.11.2024 07:03:11
NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue na...
CVE-2019-25034
- EPSS 0.73%
- Published 27.04.2021 06:15:07
- Last modified 21.11.2024 04:39:47
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot ...
CVE-2019-25042
- EPSS 0.73%
- Published 27.04.2021 06:15:07
- Last modified 21.11.2024 04:39:48
Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploite...
CVE-2019-25041
- EPSS 0.18%
- Published 27.04.2021 06:15:07
- Last modified 21.11.2024 04:39:48
Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploi...