Search CVE reports


Toggle filters

1 – 10 of 45 results


CVE-2026-44608

Medium priority

Some fixes available 3 of 4

NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Not affected Not affected Not affected
Show less packages

CVE-2026-44390

Medium priority

Some fixes available 4 of 8

Unbounded name compression in certain cases causes degradation of service

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-42959

Medium priority

Some fixes available 4 of 8

NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that can lead to a crash given malicious upstream replies. When Unbound constructs chase-reply messages for...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-42534

Medium priority

Some fixes available 4 of 8

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2026-32792

Medium priority

Some fixes available 4 of 8

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-11411

Medium priority

Some fixes available 5 of 9

NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RRSets that complement positive DNS replies in the authority section can be used to trick resolvers to update...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2025-5994

Medium priority

Some fixes available 5 of 9

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support,...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Fixed Needs evaluation Needs evaluation
Show less packages

CVE-2024-8508

Medium priority
Fixed

NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for. Malicious upstreams responses with very large RRsets can...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-43168

Medium priority
Fixed

DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Fixed Fixed
Show less packages

CVE-2024-43167

Medium priority
Fixed

DISPUTE NOTE: this issue does not pose a security risk as it (according to analysis by the original software developer, NLnet Labs) falls within the expected functionality and security controls of the application. Red Hat has made...

1 affected package

unbound

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
unbound Fixed Fixed Fixed Fixed
Show less packages