Denial of Service Vulnerability in NLnet Labs Unbound Product
CVE-2026-55717

5.9MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-55717?

The version of NLnet Labs Unbound up to 1.25.1 is vulnerable to a denial-of-service issue that occurs when the 'serve-expired: yes' option is enabled alongside specific response manipulation rules. A remote attacker controlling a delegated domain can exploit this flaw by utilizing a malicious A/AAAA record within the targeted response IP or RPZ subnet. This exploitation triggers a sequence that ultimately results in a crash due to a NULL pointer dereference, disrupting the service and compromising system stability.

Affected Version(s)

Unbound 1.10.0 < 1.25.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
Xin Wang (Northwestern Polytechnical University)
Jiapeng Li (Northwestern Polytechnical University)
Jiajia Liu (Northwestern Polytechnical University)
.