Unbound DNS Resolver Vulnerability in NLnetLabs Products
CVE-2026-77860

3.7LOW

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-77860?

In NLnetLabs Unbound versions 1.20.0 through 1.26.0, a flaw in the 'serve-expired' code path allows an attacker to exploit the wait-limit counter mechanism. By orchestrating queries from a controlled authoritative zone with short TTLs, an adversary can effectively evade the measures introduced to counteract DNSBomb attacks. This exploitation occurs through a series of 'slow' queries followed by an immediate response to expired cached names, resulting in a double decrement of the per-client wait-limit counter. By continually alternating these queries, an attacker can maintain an unlimited number of pending DNS queries from a single IP address, which can significantly disrupt service and compromise DNS resolution integrity.

Affected Version(s)

Unbound 1.20.0 < 1.26.1

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Xuanchao Xie (University of Science and Technology of China)
Lutong Chen (University of Science and Technology of China)
Kaiping Xue (University of Science and Technology of China)
.