Denial of Service Vulnerability in Unbound DNS Resolver by NLnet Labs
CVE-2026-44390
6.9MEDIUM
What is CVE-2026-44390?
A vulnerability in the Unbound DNS resolver allows attackers to exploit large Resource Record sets (RRsets) in malicious upstream responses. When Unbound attempts to apply name compression to these responses, it may become unresponsive due to the unbounded nature of the operation. Particularly, if the RRsets do not share any suffix above the root, Unbound's performance is severely impacted, leading to potential denial of service. This issue has been addressed in Unbound version 1.25.1, which introduces a fix to increment the compression counter correctly, thus preventing prolonged CPU locking and improving overall resilience against such attacks.
Affected Version(s)
Unbound 0 < 1.25.1
