Degradation of Service Vulnerability in NLnetLabs Unbound
CVE-2026-80225
5.3MEDIUM
What is CVE-2026-80225?
In NLnetLabs Unbound, a service degradation vulnerability is introduced due to the absence of limits on consecutive reads during the TCP/DoT reading procedure. This flaw allows an attacker to monopolize a worker's event loop by streaming a sequence of distinct uncached names over a TCP/DoT connection, potentially causing significant disruptions. Affected users are advised to take immediate action to mitigate risks associated with this vulnerability.
Affected Version(s)
Unbound 0 < 1.26.1
