Nlnetlabs

Unbound

67 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.58%
  • Veröffentlicht 20.05.2026 09:19:37
  • Zuletzt bearbeitet 29.07.2026 13:18:37

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow th...

  • EPSS 0.72%
  • Veröffentlicht 20.05.2026 09:19:13
  • Zuletzt bearbeitet 24.08.2026 13:18:33

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage wh...

  • EPSS 0.14%
  • Veröffentlicht 20.05.2026 09:18:41
  • Zuletzt bearbeitet 24.07.2026 10:10:00

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' a...

  • EPSS 1.27%
  • Veröffentlicht 20.05.2026 09:18:15
  • Zuletzt bearbeitet 25.08.2026 13:18:30

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a dest...

  • EPSS 0.34%
  • Veröffentlicht 20.05.2026 09:17:47
  • Zuletzt bearbeitet 24.07.2026 10:10:00

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lea...

  • EPSS 0.32%
  • Veröffentlicht 22.10.2025 12:28:02
  • Zuletzt bearbeitet 15.04.2026 00:35:42

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update their delegation infor...

  • EPSS 0.19%
  • Veröffentlicht 16.07.2025 14:38:22
  • Zuletzt bearbeitet 15.04.2026 00:35:42

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured ...

  • EPSS 0.8%
  • Veröffentlicht 03.10.2024 17:15:15
  • Zuletzt bearbeitet 17.12.2024 19:28:03

NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can cause Unbound to spend...

  • EPSS 2.52%
  • Veröffentlicht 07.03.2024 10:15:07
  • Zuletzt bearbeitet 17.12.2024 16:56:50

NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from ...

Medienbericht
  • EPSS 100%
  • Veröffentlicht 14.02.2024 16:15:45
  • Zuletzt bearbeitet 04.11.2025 19:16:14

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that,...