Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-5994
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cache poisoning via the ECS-enabled Rebirthday Attack
Source: NVD (National Vulnerability Database)
Vulnerability Description
A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-client-subnet', 'client-subnet-zone' or 'client-subnet-always-forward' options is used. Resolvers supporting ECS need to segregate outgoing queries to accommodate for different outgoing ECS information. This re-opens up resolvers to a birthday paradox attack (Rebirthday Attack) that tries to match the DNS transaction ID in order to cache non-ECS poisonous replies.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在可信数据中接受外来的不可信数据
Source: NVD (National Vulnerability Database)
Vulnerability Title
NLnet Unbound 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NLnet Unbound是荷兰NLnet团队的一款开源DNS服务器。 NLnet Unbound存在安全漏洞,该漏洞源于支持EDNS Client Subnet时存在缓存投毒风险,可能导致Rebirthday攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
NLnet LabsUnbound 1.6.2 ~ 1.23.0 -
II. Public POCs for CVE-2025-5994
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-5994
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-5994

No comments yet


Leave a comment