Denial of Service Vulnerability in NLnet Labs Unbound Product
CVE-2026-55717
5.9MEDIUM
What is CVE-2026-55717?
The version of NLnet Labs Unbound up to 1.25.1 is vulnerable to a denial-of-service issue that occurs when the 'serve-expired: yes' option is enabled alongside specific response manipulation rules. A remote attacker controlling a delegated domain can exploit this flaw by utilizing a malicious A/AAAA record within the targeted response IP or RPZ subnet. This exploitation triggers a sequence that ultimately results in a crash due to a NULL pointer dereference, disrupting the service and compromising system stability.
Affected Version(s)
Unbound 1.10.0 < 1.25.2
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Qifan Zhang (Palo Alto Networks)
Xin Wang (Northwestern Polytechnical University)
Jiapeng Li (Northwestern Polytechnical University)
Jiajia Liu (Northwestern Polytechnical University)
