Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

Unbound — Vulnerabilities & Security Advisories 21

All 21 CVE vulnerabilities found in Unbound, with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities for the Unbound DNS software product, categorized under generic weakness types and specific tag classifications. It compiles a comprehensive list of security flaws identified in Unbound, covering reports from its initial release up to the most recent updates available in current databases. By viewing these entries, users can effectively track vendor advisories and security bulletins issued by the Unbound development team. This allows administrators and security researchers to stay informed about the latest patches and configuration recommendations required to mitigate risks. Additionally, the page facilitates a deeper understanding of specific weakness classes, such as buffer overflows or memory corruption issues, by providing context on how they manifest within the Unbound codebase. Users can also look up the product’s complete vulnerability history, observing trends in flaw discovery over time to assess the long-term stability and security posture of the software. This historical perspective helps in making informed decisions regarding software upgrades and infrastructure security planning. The data presented is sourced from public vulnerability databases and official vendor notifications, ensuring accuracy and relevance. Whether you are a developer reviewing code for common pitfalls or a system administrator securing a production environment, this resource offers a centralized view of known issues. It serves as a reference for understanding the specific attack surfaces associated with Unbound and the corresponding remediation steps. The information is structured to support efficient risk management and compliance auditing processes for organizations relying on this DNS resolver.

Vendor: NLnet Labs

CVE IDTitleCVSSSeverityPublished
CVE-2026-44608 Use after free and crash under special conditions in RPZ code CWE-413--2026-05-20
CVE-2026-44390 Unbounded name compression in certain cases causes degradation of service CWE-407--2026-05-20
CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section CWE-349--2026-05-20
CVE-2026-42959 Crash during DNSSEC validation of malicious content CWE-824--2026-05-20
CVE-2026-42944 Heap overflow with multiple NSID, COOKIE, PADDING EDNS options CWE-197--2026-05-20
CVE-2026-42923 Degradation of service with unbounded NSEC3 hash calculations CWE-407--2026-05-20
CVE-2026-42534 Jostle logic bypass degrades resolution performance CWE-440--2026-05-20
CVE-2026-41292 Long list of incoming EDNS options degrades performance CWE-407--2026-05-20
CVE-2026-40622 Another 'ghost domain names' attack variant --2026-05-20
CVE-2026-33278 Possible arbitrary code execution during DNSSEC validation CWE-416--2026-05-20
CVE-2026-32792 Packet of death with DNSCrypt CWE-166--2026-05-20
CVE-2025-11411 Possible domain hijacking via promiscuous records in the authority section CWE-349 7.5AIHighAI2025-10-22
CVE-2025-5994 Cache poisoning via the ECS-enabled Rebirthday Attack CWE-349 5.3 -2025-07-16
CVE-2024-8508 Unbounded name compression could lead to Denial of Service CWE-606 5.3 Medium2024-10-03
CVE-2024-1931 Denial of service when trimming EDE text on positive replies CWE-835 7.5 High2024-03-07
CVE-2022-3204 NRDelegation Attack 7.5 -2022-09-26
CVE-2022-30699 Novel "ghost domain names" attack by updating almost expired delegation information 6.5 -2022-08-01
CVE-2022-30698 Novel "ghost domain names" attack by introducing subdomain delegations 6.5 -2022-08-01
CVE-2020-28935 Local symlink attack in Unbound and NSD CWE-59 7.8 -2020-12-07
CVE-2020-10772 Unbound 资源管理错误漏洞 CWE-406 7.5 -2020-11-27
CVE-2017-15105 Unbound 安全漏洞 CWE-358 5.3 -2018-01-23

All 21 known CVE vulnerabilities affecting Unbound with full Chinese analysis, references, and POCs where available.