PatchSiren

NLnet Labs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-56416

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:22.090Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects Unbound up to and including version 1.25.1, allowing for potential heap buffer overflows when processing DNSSEC-covered records with absent second domain names.

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-55991

A remote unauthenticated client can trigger a libngtcp2 assertion failure and terminate the Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query due to an erroneous error value passed to libngtcp2. This vulnerability affects Unbound 1.22.0 through 1.25.1 and has a CVSS score of 5.9 with a severity of MEDIUM. The vulnerability is caused by an erroneous error value passed t [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-55990

A vulnerability was found in Unbound DNSCrypt. When the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. This faulty configuration can lead to a garbage dereference when an unauthenticated client sends [truncated]

HIGH NLnet Labs CVE published 2026-07-22

CVE-2026-55973

CVE-2026-55973 is a HIGH severity vulnerability in Unbound DNS resolver software. When 'dns-error-reporting: yes' is set, an attacker can exploit the EDNS Report-Channel option to cause a stack buffer overflow, potentially terminating the daemon. One ordinary upstream response from a delegated zone controlled by the attacker is sufficient to exploit this vulnerability. The vulnerability affects Unbound ve [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-55717

A denial of service vulnerability exists in Unbound versions 1.10.0 through 1.25.1. When 'serve-expired: yes' is set along with a 'response-ip: <net> redirect' or 'response-ip-data: <net> CNAME <target>' rule, a remote client can crash the daemon. This is achieved by controlling any delegated domain and exploiting the 'serve-expired-client-timeout' callback, leading to a NULL pointer dereference and serve [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-55708

A vulnerability in NLnet Labs Unbound 1.6.0 up to and including 1.25.1 allows for the creation of a bare local zones tree for an already configured named view through the 'unbound-control' interface. This creation omits adding default-protected zones, potentially allowing queries for default-protected names to escape to the public DNS. The vulnerability impacts users of Unbound in versions 1.6.0 through 1 [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-54478

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:21.177Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects Unbound versions 1.18.0 through 1.25.1, specifically when configured with a 'proxy-protocol-port' interface and 'answer-cookie: yes'. The server-cookie SipHash is compute [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-52863

A memory corruption vulnerability exists in Unbound 1.25.0-1.25.1. The issue arises from a shallow copy of the view name in effect, which could lead to memory corruption if the owner of the original view name is jostled out when Unbound is under pressure. This vulnerability requires specific configurations, including 'respip'/'rpz' modules, 'access-control-view', and subquery modules like 'respip CNAME re [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-50252

CVE-2026-50252 is a DNS cache poisoning vulnerability affecting Unbound versions 1.4.22 through 1.25.1. The issue arises when load balancing policies depend on the source UDP port while revealing their outcome, undermining the secrecy of DNS transactions. This occurs when the SO_REUSEPORT configuration option is enabled, allowing for deterministic assignment of incoming DNS queries to specific worker thre [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-50251

CVE-2026-50251 is a vulnerability in Unbound DNS software that allows a remote attacker to trigger a cache clear of the message and rrset caches indefinitely, potentially leading to a denial-of-service condition. The vulnerability exists when 'unwanted-reply-threshold' is enabled and a malicious actor controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0. This can cause Unbound to loop and c [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-50243

A vulnerability was found in NLnet Labs Unbound, a popular DNS resolver. The issue occurs when Unbound is configured with the 'respip' module and a 'response-ip' redirect rule or RPZ file with an RPZ-IP trigger. In such cases, the rewriting handler does not verify the security status of the upstream answer. Consequently, a BOGUS A/AAAA answer can be rewritten to point to an operator's configured IP, poten [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-50046

CVE-2026-50046 is a denial of service vulnerability affecting Unbound versions 1.15.0 through 1.25.1. The vulnerability occurs when handling DNS-over-TLS (DoT) forwarded queries. A malicious actor could exploit this by querying records in a specific zone while keeping Unbound under pressure, leading to a daemon crash. The vulnerability arises from the TLS server name used for DoT forwarded queries being t [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-46582

A vulnerability in Unbound 1.6.0 up to and including 1.25.1 allows for DNSSEC secure cache poisoning through replay of a wildcard rrset. This issue arises when a replay of a wildcard rrset as another piece of data could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. The vulnerability occurs [truncated]

HIGH NLnet Labs CVE published 2026-07-22

CVE-2026-44690

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:19.153Z and has not been modified since then. This vulnerability affects NLnet Labs Unbound versions 1.7.0 through 1.25.1, allowing for cache poisoning attacks due to insufficient validation of the RRSIG.Labels field. The vulnerability has a high CVSS score of 7.5 and is classified as HIGH [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-44687

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:19.040Z and has not been modified since then. This vulnerability affects Unbound versions 1.13.2 through 1.25.1, where an off-by-one error in 'harden-below-nxdomain' logic could allow an attacker to bypass DNSSEC NXDOMAIN checks. Organizations should verify their configurations and consider [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-44621

A vulnerability in Unbound's libunbound, when configured with 'unwanted-reply-threshold', could lead to abrupt termination if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup'. This function is absent from the function call allow list, resulting in a fatal exit of libunbound and eventual termination of the embedding application.

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-42955

CVE-2026-42955 is a 'ghost domain names' vulnerability in Unbound 1.16.2 through 1.25.1. An adversary controlling a ghost zone can query a vulnerable Unbound to extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. In configurations with 'harden-referral-path: yes', no client query is required. This vulnerability is a variant of CVE-2026-40622, which only address [truncated]

LOW NLnet Labs CVE published 2026-07-22

CVE-2026-41637

A vulnerability in Unbound 1.22.0-1.25.1 can cause DNS-over-QUIC (DoQ) queries to be improperly accounted for, leading to service degradation for new clients. This occurs when client-terminated DoQ queries are not properly counted, causing an inflation of waiting replies for in-flight resolution queries. Exploitation requires Unbound to be compiled with DoQ support and configured to listen on a QUIC port. [truncated]

HIGH NLnet Labs CVE published 2026-07-22

CVE-2026-40691

CVE-2026-40691 is a denial-of-service vulnerability in Unbound versions 1.9.0 through 1.25.1. The issue arises when a DNSCrypt query is received over TCP, and the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. This can lead to a crash of the resolver. The vulnerability requires Unbound to be compiled with DNSCrypt support and the 'dnscrypt:' c [truncated]

HIGH NLnet Labs CVE published 2026-07-22

CVE-2026-32665

A remote denial of service vulnerability exists in NLnet Labs Unbound 1.22.0 through 1.25.1 when DNS-over-QUIC (DoQ) is enabled. The vulnerability allows a remote client to bypass the 'quic-size' limit, leading to excessive memory allocation and potential denial of service for new DoQ clients. This issue arises from the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypassing [truncated]

MEDIUM NLnet Labs CVE published 2026-07-22

CVE-2026-14586

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:15.020Z and has not been modified since then. This vulnerability affects Unbound versions 1.22.0 to 1.25.1 with DNS-over-QUIC (DoQ) support enabled. The vulnerability can lead to server termination and denial of service under high concurrency and pressure in DoQ environments. The issue aris [truncated]

HIGH NLnet Labs CVE published 2026-06-10

CVE-2026-10846

CVE-2026-10846 is a HIGH-severity vulnerability in NLnet Labs ldns, a DNS library used for DNS resolution. Versions 1.2.0 through 1.9.0 are affected when used as a (stub) resolver over UDP. The vulnerability allows for off-path poisoning attacks due to a lack of matching between query and response source addresses, ports, query IDs, and questions.

HIGH NLnet Labs CVE published 2026-06-08

CVE-2026-49234

CVE-2026-49234 is a HIGH severity vulnerability in Routinator that causes a crash when a specifically crafted non-UTF-8 string is sent as a select-asn query parameter to the /api/v1/origins endpoint. This issue only affects users who allow API access from untrusted networks. The vulnerability was published on [cvePublishedAt] and modified on [cveModifiedAt].

HIGH NLnet Labs CVE published 2026-06-08

CVE-2026-49232

CVE-2026-49232 is a high-severity vulnerability in Routinator, a software used for RPKI-based BGP route validation. The vulnerability has a CVSS score of 8.7 and can cause a denial of service (DoS) condition when accepting incoming HTTP or RTR connections. An attacker can trigger this condition by opening a large number of connections to the HTTP or RTR server, causing the software to exit on any error, i [truncated]

MEDIUM NLnet Labs CVE published 2026-05-20

CVE-2026-44608

CVE-2026-44608 describes a locking inconsistency in NLnet Labs Unbound that can lead to a heap use-after-free and eventual crash when specific conditions line up: the resolver is multi-threaded, an RPZ zone uses rpz-nsip or rpz-nsdname triggers, and an XFR reload of that RPZ zone is happening at the same time another thread reads the zone. The issue does not apply to local RPZ files. NLnet Labs states tha [truncated]

MEDIUM NLnet Labs CVE published 2026-05-20

CVE-2026-44390

CVE-2026-44390 is a denial-of-service issue in NLnet Labs Unbound. According to the vendor advisory and NVD, Unbound up to and including 1.25.0 can spend a considerable amount of CPU time applying name compression to replies containing very large RRsets, especially when the records do not share a suffix above the root. In well-orchestrated attacks, this can degrade performance and eventually lead to servi [truncated]

HIGH NLnet Labs CVE published 2026-05-20

CVE-2026-42959

CVE-2026-42959 is a high-severity denial-of-service issue in NLnet Labs Unbound’s DNSSEC validator. A crafted upstream response can trigger an immediate crash in versions up to and including 1.25.0; Unbound 1.25.1 contains the fix.

HIGH NLnet Labs CVE published 2026-05-20

CVE-2026-42944

CVE-2026-42944 is a network-exploitable heap overflow in NLnet Labs Unbound affecting versions 1.14.0 through 1.25.0. The issue can be triggered by a client that can query Unbound and supplies multiple NSID, DNS Cookie, and/or EDNS Padding options, but only when the relevant EDNS features are enabled. NLnet Labs states Unbound 1.25.1 contains the fix.

MEDIUM NLnet Labs CVE published 2026-05-20

CVE-2026-42923

NLnet Labs Unbound versions 1.19.1 through 1.25.0 contain a DNSSEC validator issue where the negative-cache path for DS records does not apply the NSEC3 hash-calculation limit introduced in 1.19.1. According to the vendor and NVD, this can cause excessive hashing work and hold a global negative-cache lock long enough to block other threads, creating a denial-of-service condition under coordinated attack. [truncated]

MEDIUM NLnet Labs CVE published 2026-05-20

CVE-2026-42534

CVE-2026-42534 is a network-reachable availability issue in NLnet Labs Unbound up to and including 1.25.0. According to the published CVE description and NVD metadata, duplicate retransmits of the same query can refresh the apparent age of slow queries, which can interfere with Unbound’s jostle logic when the per-thread query limit is reached. The result is degraded resolution performance, and coordinated [truncated]

MEDIUM NLnet Labs CVE published 2026-05-20

CVE-2026-41292

CVE-2026-41292 affects NLnet Labs Unbound up to and including 1.25.0. A remote attacker can send queries with excessive EDNS options to keep Unbound threads busy while the resolver parses the options and builds internal data structures, which can degrade service or cause denial of service. Unbound 1.25.1 includes a fix that limits acceptable incoming EDNS options to 100.

MEDIUM NLnet Labs CVE published 2026-05-20

CVE-2026-40622

CVE-2026-40622 describes a DNS resolver integrity issue in NLnet Labs Unbound affecting versions 1.16.2 through 1.25.0. In the described ghost-domain attack family, a remote adversary who controls a ghost zone and can query a vulnerable resolver may cause an expired parent-side referral NS RRset in cache to be replaced with a child-side apex NS RRset, extending the ghost-domain window by up to one configu [truncated]

MEDIUM NLnet Labs CVE published 2026-05-20

CVE-2026-32792

CVE-2026-32792 affects NLnet Labs Unbound versions 1.6.2 through 1.25.0 when compiled with DNSCrypt support (--enable-dnscrypt). According to the vendor and NVD, a single malformed DNSCrypt query whose decrypted plaintext is all 0x00 bytes and lacks the expected 0x80 marker can underflow the packet-reading logic, potentially causing a heap overflow and a crash. NLnet Labs states that version 1.25.1 fixes [truncated]