Denial of Service Vulnerability in NLnet Labs Unbound DNS Resolver
CVE-2026-50046
5.9MEDIUM
What is CVE-2026-50046?
In certain versions of NLnet Labs Unbound, a vulnerability exists that can lead to a Denial of Service due to improper management of memory during the TLS handshake for DNS-over-TLS queries. This flaw arises when the server node managing queries is pushed out of the mesh while still engaged in the TLS handshake process. If an error occurs during this process, it can cause the application to crash as it attempts to dereference a freed memory pointer. An attacker knowing the Unbound configuration can exploit this vulnerability by sending strategically-timed queries, which may induce a crash of the DNS resolver, thereby disrupting service.
Affected Version(s)
Unbound 1.15.0 < 1.25.2
