Fault in Unbound DNS Resolver by NLnet Labs Leading to Service Degradation
CVE-2026-56444

5.9MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-56444?

The Unbound DNS resolver, specifically versions 1.20.0 through 1.25.1, has a flaw that affects systems configured with 'serve-expired: yes' and a misconfigured 'serve-expired-client-timeout' in relation to 'discard-timeout'. In scenarios where the discard-timeout is greater than the serve-expired-client-timeout, the resolver fails to properly manage the counter for reply addresses. This mismanagement can lead to silence drop-offs for new clients making similar queries, severely affecting DNS resolution performance. An attacker may exploit this by issuing queries to a client-controlled DNS zone, potentially overwhelming the resolver and causing a significant degradation of service, thus impacting users reliant on DNS resolution.

Affected Version(s)

Unbound 1.20.0 < 1.25.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
Xin Wang (Northwestern Polytechnical University)
Jiapeng Li (Northwestern Polytechnical University)
Jiajia Liu (Northwestern Polytechnical University)
Haruki Oyama (Waseda University)
.