Unbound jostle logic vulnerability affects NLnet Labs product
CVE-2026-42534

6.9MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-42534?

NLnet Labs Unbound versions up to and including 1.25.0 exhibit a vulnerability in their jostle logic, which is essential for maintaining efficient query resolution. This flaw can be exploited by an attacker controlling a slow-responding domain name server. When exposed, duplicate queries can confuse the aging process, allowing slower responses to remain in play and degrade overall resolution performance. The issue can potentially lead to coordinated attacks aimed at creating a denial of resolution service. The subsequent version, Unbound 1.25.1, addresses this vulnerability by implementing a corrected mechanism to ensure that timestamps from initial queries are accurately preserved, enabling the jostle logic to function correctly.

Affected Version(s)

Unbound 0 < 1.25.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.