Unbound DNS Resolver Vulnerability in NLnetLabs Products
CVE-2026-77860
What is CVE-2026-77860?
In NLnetLabs Unbound versions 1.20.0 through 1.26.0, a flaw in the 'serve-expired' code path allows an attacker to exploit the wait-limit counter mechanism. By orchestrating queries from a controlled authoritative zone with short TTLs, an adversary can effectively evade the measures introduced to counteract DNSBomb attacks. This exploitation occurs through a series of 'slow' queries followed by an immediate response to expired cached names, resulting in a double decrement of the per-client wait-limit counter. By continually alternating these queries, an attacker can maintain an unlimited number of pending DNS queries from a single IP address, which can significantly disrupt service and compromise DNS resolution integrity.
Affected Version(s)
Unbound 1.20.0 < 1.26.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
