CVE-2026-50251
- EPSS 0.25%
- Veröffentlicht 22.07.2026 13:08:43
- Zuletzt bearbeitet 24.07.2026 14:05:26
In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS ...
CVE-2026-50248
- EPSS 0.13%
- Veröffentlicht 22.07.2026 13:08:32
- Zuletzt bearbeitet 24.07.2026 13:59:37
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA r...
CVE-2026-50243
- EPSS 0.13%
- Veröffentlicht 22.07.2026 13:08:21
- Zuletzt bearbeitet 24.07.2026 13:59:07
In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not ch...
CVE-2026-50046
- EPSS 0.24%
- Veröffentlicht 22.07.2026 13:08:08
- Zuletzt bearbeitet 24.07.2026 13:55:29
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct...
CVE-2026-50045
- EPSS 0.28%
- Veröffentlicht 22.07.2026 13:07:55
- Zuletzt bearbeitet 24.07.2026 13:58:11
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effecti...
CVE-2026-46582
- EPSS 0.18%
- Veröffentlicht 22.07.2026 13:07:40
- Zuletzt bearbeitet 24.07.2026 13:55:34
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bo...
CVE-2026-44690
- EPSS 0.15%
- Veröffentlicht 22.07.2026 13:06:56
- Zuletzt bearbeitet 24.07.2026 13:57:55
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controll...
CVE-2026-44687
- EPSS 0.22%
- Veröffentlicht 22.07.2026 13:06:42
- Zuletzt bearbeitet 24.07.2026 13:56:10
In NLnet Labs Unbound 1.13.2 up to and including 1.25.1, stub or forward zones where the name is below an intermediate labed below a DNSSEC signed zone could be shadowed by the intermediate label's secure NXDOMAIN answer from the parent. This is caus...
CVE-2026-44621
- EPSS 0.25%
- Veröffentlicht 22.07.2026 13:06:28
- Zuletzt bearbeitet 24.07.2026 13:56:30
With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_allo...
CVE-2026-42955
- EPSS 0.28%
- Veröffentlicht 22.07.2026 13:05:53
- Zuletzt bearbeitet 24.07.2026 13:56:42
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured va...