Denial of Service Vulnerability in NLnet Labs Unbound DNS Resolver
CVE-2026-50046

5.9MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-50046?

In certain versions of NLnet Labs Unbound, a vulnerability exists that can lead to a Denial of Service due to improper management of memory during the TLS handshake for DNS-over-TLS queries. This flaw arises when the server node managing queries is pushed out of the mesh while still engaged in the TLS handshake process. If an error occurs during this process, it can cause the application to crash as it attempts to dereference a freed memory pointer. An attacker knowing the Unbound configuration can exploit this vulnerability by sending strategically-timed queries, which may induce a crash of the DNS resolver, thereby disrupting service.

Affected Version(s)

Unbound 1.15.0 < 1.25.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.