PT-2026-63383 · Nlnet · Unbound

·

CVE-2026-50251

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions prior to 1.25.2
Description When the unwanted-reply-threshold is enabled and set to a value greater than zero, the software is susceptible to a cache clearing attack. A malicious actor controlling a delegation that returns in-bailiwick glue records of 0.0.0.0/::0 can trigger a defensive cache clear of the message and rrset caches. This occurs because the system may route traffic for 0.0.0.0/::0 via loopback, causing the listener to answer from 127.0.0.1. The mismatch between the source IP 0.0.0.0 and the reply IP 127.0.0.1 leads the software to categorize the reply as unwanted. By repeatedly triggering this behavior, an attacker can force the unwanted-reply-threshold counter to its limit, clearing the cache indefinitely without needing to send spoofed packets.
Recommendations Update to version 1.25.2 or later. As a temporary mitigation, set the unwanted-reply-threshold to zero to disable the affected functionality.

Fix

DoS

Incomplete List of Disallowed Inputs

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92979
CVE-2026-50251
ECHO-B852-F6A0-98DC
OESA-2026-3333
OESA-2026-3334
OESA-2026-3335
OESA-2026-3336
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound