Denial of Service Risk in NLnet Labs Unbound 1.25.1 and Earlier
CVE-2026-44621

5.9MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-44621?

The Denial of Service vulnerability in NLnet Labs Unbound, specifically in versions up to 1.25.1, can cause applications utilizing libunbound to terminate unexpectedly when configured with an 'unwanted-reply-threshold'. If this threshold is exceeded due to a barrage of incorrect UDP datagrams with wrong transaction IDs, the necessary cleanup function 'libworker_alloc_cleanup' is triggered, leading to a fatal exit of libunbound. However, Unbound itself remains operational since its corresponding function is correctly registered in the allow list, preventing service disruption.

Affected Version(s)

Unbound 0 < 1.25.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.