NLnet Labs Unbound是荷兰NLnet Labs组织的域名系统解析服务器。 NLnet Labs Unbound 1.6.2版本及之前版本至1.25.1版本存在信任管理问题漏洞,该漏洞源于'respip'模块中的重写处理器未检查上游应答的安全状态,可能将BOGUS A/AAAA应答重写为操作员配置的IP,导致客户端收到不安全的NOERROR回复,恶意行为者可通过伪造落入操作员配置子网的BOGUS A/AAAA应答利用此投毒效果。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NLnet Labs | Unbound | 1.6.2< 1.25.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| NLnet Labs | Unbound | 1.6.2 ~ 1.25.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55973 | 7.5 HIGH | 'dns-error-reporting: yes' leads to stack buffer overflow |
| CVE-2026-32665 | 7.5 HIGH | Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass |
| CVE-2026-40691 | 7.5 HIGH | Packet of death for DNSCrypt over TCP |
| CVE-2026-44690 | 7.5 HIGH | Cross-zone wildcard cache poisoning via RRSIG.labels manipulation |
| CVE-2026-50248 | 6.5 MEDIUM | BOGUS configured primary hostname accepted for XFR in auth/rpz zones |
| CVE-2026-55991 | 5.9 MEDIUM | Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 |
| CVE-2026-14586 | 5.9 MEDIUM | Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments |
| CVE-2026-56444 | 5.9 MEDIUM | Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout |
| CVE-2026-44621 | 5.9 MEDIUM | Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abr |
| CVE-2026-55990 | 5.9 MEDIUM | Packet of death for a DNSCrypt misconfigured Unbound |
| CVE-2026-50046 | 5.9 MEDIUM | Possible heap use-after-free in an error path when a DoT forwarded query is jostled out |
| CVE-2026-55717 | 5.9 MEDIUM | 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash |
| CVE-2026-52863 | 5.9 MEDIUM | Memory corruption could lead to crash and denial of service |
| CVE-2026-50045 | 5.3 MEDIUM | 'max-global-quota' reset by DNSSEC validation restarts |
| CVE-2026-50251 | 5.3 MEDIUM | Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush |
| CVE-2026-56416 | 4.8 MEDIUM | Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name |
| CVE-2026-46582 | 3.7 LOW | A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply |
| CVE-2026-44687 | 3.7 LOW | Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legi |
| CVE-2026-41637 | 3.7 LOW | Degradation of resolution service from improperly accounted client-terminated DNS-over-QUI |
| CVE-2026-54478 | 3.7 LOW | DNS Cookie bypass when combined with proxy-protocol use |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet