Vulnerability Description
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nlnetlabs | Unbound | >= 1.22.0, < 1.25.2 |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-50045?
CVE-2026-50045 is a vulnerability with a CVSS score of 5.3 (MEDIUM). In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query th...
How severe is CVE-2026-50045?
CVE-2026-50045 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-50045?
Check the references section above for vendor advisories and patch information. Affected products include: Nlnetlabs Unbound.