Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

unbound — Vulnerabilities & Security Advisories 45

All 45 CVE vulnerabilities found in unbound, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumerations associated with Unbound, an authoritative DNS recursive caching server developed by NLnet Labs. It collects security vulnerabilities categorized under various Common Weakness Types, covering a historical time range from initial public disclosures up to the most recent updates. Here, users can track vendor advisories issued by the Unbound maintainers to stay informed about critical patches and security updates. Additionally, visitors can gain a deeper understanding of specific weakness classes that affect DNS resolution software, analyzing patterns in how these flaws are exploited or mitigated. The resource also serves as a reference for looking up the vulnerability history of the Unbound product, allowing security researchers and system administrators to assess the long-term security posture of the software. By centralizing this information, the page facilitates efficient risk management and helps IT professionals prioritize remediation efforts based on severity and relevance. The data is structured to support both high-level overviews and detailed technical investigations, ensuring that stakeholders can make informed decisions regarding deployment configurations and update schedules. This compilation aims to enhance transparency and improve the overall security landscape for users relying on Unbound for DNS infrastructure.

Vendor: NLnet Labs

CVE ID Title CVSS Severity Published
CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration CWE-772 5.9 Medium 2026-07-22
CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name CWE-354 4.8 Medium 2026-07-22
CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2 CWE-195 5.9 Medium 2026-07-22
CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound CWE-457 5.9 Medium 2026-07-22
CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow CWE-20 7.5 High 2026-07-22
CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash CWE-476 5.9 Medium 2026-07-22
CVE-2026-55708 Privacy/configuration issue when adding local data in views through 'unbound-control' CWE-1188 3.1 Low 2026-07-22
CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use CWE-290 3.7 Low 2026-07-22
CVE-2026-52863 Memory corruption could lead to crash and denial of service CWE-416 5.9 Medium 2026-07-22
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread CWE-349 - - 2026-07-22
CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush CWE-184 5.3 Medium 2026-07-22
CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones CWE-345 6.5 Medium 2026-07-22
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL CWE-348 - - 2026-07-22
CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out CWE-416 5.9 Medium 2026-07-22
CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts CWE-406 5.3 Medium 2026-07-22
CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path CWE-358 3.7 Low 2026-07-22
CVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulation CWE-345 7.5 High 2026-07-22
CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN CWE-193 3.7 Low 2026-07-22
CVE-2026-44621 Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated CWE-754 5.9 Medium 2026-07-22
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records CWE-672 3.7 Low 2026-07-22
CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries CWE-772 3.7 Low 2026-07-22
CVE-2026-40691 Packet of death for DNSCrypt over TCP CWE-122 7.5 High 2026-07-22
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass CWE-1284 7.5 High 2026-07-22
CVE-2026-14586 Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments CWE-617 5.9 Medium 2026-07-22
CVE-2026-44608 Use after free and crash under special conditions in RPZ code CWE-413 - - 2026-05-20
CVE-2026-44390 Unbounded name compression in certain cases causes degradation of service CWE-407 6.9 Medium 2026-05-20
CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section CWE-349 - - 2026-05-20
CVE-2026-42959 Crash during DNSSEC validation of malicious content CWE-824 8.7 High 2026-05-20
CVE-2026-42944 Heap overflow with multiple NSID, COOKIE, PADDING EDNS options CWE-197 8.7 High 2026-05-20
CVE-2026-42923 Degradation of service with unbounded NSEC3 hash calculations CWE-407 - - 2026-05-20

All 45 known CVE vulnerabilities affecting unbound with full Chinese analysis, references, and POCs where available.