VendorsNLnet Labsunboundall versions
Vulnerabilities

NLnet Labs Unbound

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

73CVEs
CVE-2026-42960
Possible cache poisoning via promiscuous records for the authority section
Published 2026-05-20 · Analyzed
10.0EPSS 0.003
CVE-2019-25032
Unbound before 1.9.5 allows an integer overflow in the regional allocator via regional_alloc. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
9.8EPSS 0.022
CVE-2019-25034
Unbound before 1.9.5 allows an integer overflow in sldns_str2wire_dname_buf_origin, leading to an out-of-bounds write. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
9.8EPSS 0.020
CVE-2019-25039
Unbound before 1.9.5 allows an integer overflow in a size calculation in respip/respip.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
9.8EPSS 0.020
CVE-2019-25038
Unbound before 1.9.5 allows an integer overflow in a size calculation in dnscrypt/dnscrypt.c. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
9.8EPSS 0.020
CVE-2019-25035
Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
9.8EPSS 0.020
CVE-2019-25042
Unbound before 1.9.5 allows an out-of-bounds write via a compressed name in rdata_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
9.8EPSS 0.020
CVE-2019-25033
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
9.8EPSS 0.018
CVE-2026-33278
Possible arbitrary code execution during DNSSEC validation
Published 2026-05-20 · Modified
9.8EPSS 0.011
CVE-2026-81642
Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY
Published 2026-09-16 · Analyzed
9.8EPSS 0.010
CVE-2026-82717
CNAME synthesis could lead to heap corruption
Published 2026-09-16 · Analyzed
9.8EPSS 0.008
CVE-2026-50252
Possible cache poisoning attack by mapping source port population per thread
Published 2026-07-22 · Analyzed
9.3EPSS 0.002
CVE-2026-42944
Heap overflow with multiple NSID, COOKIE, PADDING EDNS options
Published 2026-05-20 · Modified
8.7EPSS 0.008
CVE-2026-42959
Crash during DNSSEC validation of malicious content
Published 2026-05-20 · Modified
8.7EPSS 0.007
CVE-2023-50387
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Published 2024-02-14 · Modified
7.5EPSS 1.000
CVE-2020-12663
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
Published 2020-05-19 · Modified
7.5EPSS 0.036
CVE-2019-16866
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
Published 2019-10-03 · Modified
7.5EPSS 0.035
CVE-2020-12662
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
Published 2020-05-19 · Modified
7.5EPSS 0.032
CVE-2009-3602
Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.
Published 2009-10-13 · Modified
7.5EPSS 0.030
CVE-2024-1931
Denial of service when trimming EDE text on positive replies
Published 2024-03-07 · Analyzed
7.5EPSS 0.025
CVE-2019-25041
Unbound before 1.9.5 allows an assertion failure via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
7.5EPSS 0.021
CVE-2019-25037
Unbound before 1.9.5 allows an assertion failure and denial of service in dname_pkt_copy via an invalid packet. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
7.5EPSS 0.021
CVE-2019-25040
Unbound before 1.9.5 allows an infinite loop via a compressed name in dname_pkt_copy. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
7.5EPSS 0.020
CVE-2019-25036
Unbound before 1.9.5 allows an assertion failure and denial of service in synth_cname. NOTE: The vendor disputes that this is a vulnerability. Although the code may be vulnerable, a running Unbound installation cannot be remotely or locally exploited
Published 2021-04-27 · Modified
7.5EPSS 0.020
CVE-2022-3204
NRDelegation Attack
Published 2022-09-26 · Modified
7.5EPSS 0.016
CVE-2020-10772
An incomplete fix for CVE-2020-12662 was shipped for Unbound in Red Hat Enterprise Linux 7, as part of erratum RHSA-2020:2414. Vulnerable versions of Unbound could still amplify an incoming query into a large number of queries directed to a target, even with a lower amplification ratio compared to versions of Unbound that shipped before the mentioned erratum. This issue is about the incomplete fix for CVE-2020-12662, and it does not affect upstream versions of Unbound.
Published 2020-11-27 · Modified
7.5EPSS 0.013
CVE-2026-41292
Long list of incoming EDNS options degrades performance
Published 2026-05-20 · Modified
7.5EPSS 0.008
CVE-2026-42534
Jostle logic bypass degrades resolution performance
Published 2026-05-20 · Modified
7.5EPSS 0.007
CVE-2026-44390
Unbounded name compression in certain cases causes degradation of service
Published 2026-05-20 · Modified
7.5EPSS 0.007
CVE-2026-85501
Retrap: Novel Vulnerabilities to launch Algorithmic Complexity Attacks on DNSSEC
Published 2026-09-16 · Analyzed
7.5EPSS 0.005
CVE-2026-80225
Possible degradation of service from continuous queries on the same TCP/DoT connection
Published 2026-09-16 · Analyzed
7.5EPSS 0.005
CVE-2026-81634
Possible heap buffer overflow during DNSSEC canonicalization
Published 2026-09-16 · Analyzed
7.5EPSS 0.005
CVE-2026-32665
Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
Published 2026-07-22 · Analyzed
7.5EPSS 0.005
CVE-2026-40691
Packet of death for DNSCrypt over TCP
Published 2026-07-22 · Analyzed
7.5EPSS 0.005
CVE-2026-55973
'dns-error-reporting: yes' leads to stack buffer overflow
Published 2026-07-22 · Analyzed
7.5EPSS 0.005
CVE-2026-40622
Another 'ghost domain names' attack variant
Published 2026-05-20 · Analyzed
7.5EPSS 0.002
CVE-2026-44690
Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
Published 2026-07-22 · Analyzed
7.5EPSS 0.001
CVE-2019-18934
Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in the configuration.
Published 2019-11-19 · Modified
7.3EPSS 0.032
CVE-2026-42923
Degradation of service with unbounded NSEC3 hash calculations
Published 2026-05-20 · Analyzed
6.9EPSS 0.004
CVE-2022-30698
Novel "ghost domain names" attack by introducing subdomain delegations
Published 2022-08-01 · Modified
6.5EPSS 0.011
1 / 2Next →