DNS Cache Poisoning Vulnerability in NLnet Labs Unbound Software
CVE-2026-50252

5.7MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-50252?

In NLnet Labs Unbound versions from 1.4.22 to 1.25.1, the UDP source port is randomized to enhance the confidentiality of DNS transactions. However, if resolver load balancing decisions are based on the source port, this mechanism can unintentionally expose the system to risks. The use of the SO_REUSEPORT configuration allows a determined attacker to exploit the predictable assignment of UDP source ports, rendering the system vulnerable to DNS cache poisoning attacks. By correlating the source UDP port and worker threads, an attacker can predictably lower the entropy of source port assignments, enabling malicious activities that compromise DNS resolution security.

Affected Version(s)

Unbound 1.4.22 < 1.25.2

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Inbal Schussheim (Hebrew University)
Amit Klein (Hebrew University)
.