Cache Poisoning Vulnerability in Unbound DNS Resolvers - Unbound Software
CVE-2025-5994

8.7HIGH

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
16 July 2025

What is CVE-2025-5994?

A significant cache poisoning vulnerability has been identified in Unbound DNS resolvers that utilize EDNS Client Subnet (ECS) support. Named the 'Rebirthday Attack', this vulnerability allows attackers to exploit resolver configurations that send ECS information to upstream name servers. By manipulating outgoing queries, malicious actors can inject non-ECS poisonous replies by matching DNS transaction IDs, ultimately compromising the integrity of the DNS cache. This flaw underscores the necessity for resolvers to implement stringent segregation of outgoing queries to mitigate the risks associated with this type of attack.

Affected Version(s)

Unbound 1.6.2 < 1.23.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xiang Li (AOSP Lab, Nankai University)
.
CVE-2025-5994 : Cache Poisoning Vulnerability in Unbound DNS Resolvers - Unbound Software