VendorsNLnet Labsunboundall versions
Vulnerabilities

NLnet Labs Unbound

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

73CVEs
CVE-2022-30699
Novel "ghost domain names" attack by updating almost expired delegation information
Published 2022-08-01 · Modified
6.5EPSS 0.011
CVE-2026-78227
Use-after-free in DoQ stream output buffer on reset re-transmission
Published 2026-09-16 · Analyzed
6.5EPSS 0.003
CVE-2026-50248
BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Published 2026-07-22 · Analyzed
6.5EPSS 0.002
CVE-2026-50243
'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
Published 2026-07-22 · Analyzed
6.3EPSS 0.001
CVE-2019-25031
Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation
Published 2021-04-27 · Analyzed
5.9EPSS 0.013
CVE-2026-82720
Use-after-free in DoH stream cleanup code path
Published 2026-09-16 · Analyzed
5.9EPSS 0.004
CVE-2026-50046
Possible heap use-after-free in an error path when a DoT forwarded query is jostled out
Published 2026-07-22 · Analyzed
5.9EPSS 0.004
CVE-2026-44621
Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated
Published 2026-07-22 · Analyzed
5.9EPSS 0.004
CVE-2026-52863
Memory corruption could lead to crash and denial of service
Published 2026-07-22 · Analyzed
5.9EPSS 0.004
CVE-2026-55717
'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
Published 2026-07-22 · Analyzed
5.9EPSS 0.004
CVE-2026-55990
Packet of death for a DNSCrypt misconfigured Unbound
Published 2026-07-22 · Analyzed
5.9EPSS 0.004
CVE-2026-55991
Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
Published 2026-07-22 · Analyzed
5.9EPSS 0.004
CVE-2026-56444
Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
Published 2026-07-22 · Undergoing Analysis
5.9EPSS 0.004
CVE-2026-44608
Use after free and crash under special conditions in RPZ code
Published 2026-05-20 · Analyzed
5.9EPSS 0.003
CVE-2020-28935
Local symlink attack in Unbound and NSD
Published 2020-12-07 · Modified
5.5EPSS 0.005
CVE-2017-15105
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick unbound into accepting a NODATA proof.
Published 2018-01-23 · Modified
5.3EPSS 0.026
CVE-2024-8508
Unbounded name compression could lead to Denial of Service
Published 2024-10-03 · Analyzed
5.3EPSS 0.008
CVE-2026-50045
'max-global-quota' reset by DNSSEC validation restarts
Published 2026-07-22 · Analyzed
5.3EPSS 0.005
CVE-2026-50251
Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
Published 2026-07-22 · Analyzed
5.3EPSS 0.004
CVE-2026-32792
Packet of death with DNSCrypt
Published 2026-05-20 · Analyzed
5.3EPSS 0.004
CVE-2009-4008
Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.
Published 2011-06-02 · Modified
5.0EPSS 0.027
CVE-2010-0969
Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
Published 2010-03-16 · Modified
5.0EPSS 0.026
CVE-2026-56416
Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
Published 2026-07-22 · Analyzed
4.8EPSS 0.001
CVE-2026-77955
Possible ZONEMD verification bypass window
Published 2026-09-16 · Analyzed
4.4EPSS 0.002
CVE-2014-8602
iterator.c in NLnet Labs Unbound before 1.5.1 does not limit delegation chaining, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a large or infinite number of referrals.
Published 2014-12-11 · Modified
4.3EPSS 0.252
CVE-2011-1922
daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.
Published 2011-05-31 · Modified
4.3EPSS 0.071
CVE-2026-41637
Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
Published 2026-07-22 · Analyzed
3.7EPSS 0.004
CVE-2026-44687
Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
Published 2026-07-22 · Analyzed
3.7EPSS 0.003
CVE-2026-77860
'serve-expired' can bypass Unbound 'wait-limit'
Published 2026-09-16 · Analyzed
3.7EPSS 0.003
CVE-2026-42955
Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
Published 2026-07-22 · Analyzed
3.7EPSS 0.003
CVE-2026-46582
A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
Published 2026-07-22 · Analyzed
3.7EPSS 0.003
CVE-2026-54478
DNS Cookie bypass when combined with proxy-protocol use
Published 2026-07-22 · Analyzed
3.7EPSS 0.002
CVE-2026-55708
Privacy/configuration issue when adding local data in views through 'unbound-control'
Published 2026-07-22 · Analyzed
3.1EPSS 0.002
← Prev2 / 2