Nlnet · Unbound · CVE-2026-50045
**Name of the Vulnerable Software and Affected Versions**
NLnet Labs Unbound versions 1.22.0 through 1.25.1
**Description**
A client query for a deeply nested name under a DNSSEC-signed parent allows the system to send more upstream packets per query than the `max-global-quota` configuration allows. This behavior bypasses the security setting intended to limit upstream amplification traffic, which is traffic used in amplification attacks to overwhelm a target with a large volume of data.
**Recommendations**
Update NLnet Labs Unbound to a version later than 1.25.1.