PT-2026-93368 · Nlnetlabs · Unbound

·

CVE-2026-77860

·

Published

2026-09-16

·

Updated

2026-09-29

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions NLnetLabs Unbound versions 1.20.0 through 1.26.0
Description A flaw in the 'serve-expired' code path allows a double decrement of the wait-limit counter per client IP. An attacker can exploit this by controlling an authoritative zone with short Time to Live (TTL) values to ensure cached entries expire rapidly. By alternating between slow queries (which the attacker's authoritative server never answers) and pump queries (queries for expired cached names answered via the 'serve-expired' path), the attacker can keep the per-client counter at or below the wait-limit indefinitely. This allows a single source IP to maintain an arbitrary number of pending queries up to the global mesh quota num-queries-per-thread, bypassing a counter measure designed to prevent DNSBomb attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-101718
CVE-2026-77860
ECHO-A935-81B8-4EAE
OPENSUSE-SU-2026:11930-1
RHSA-2026:68590

Affected Products

Unbound