Unbound
This hub aggregates every CVE we track for Unbound, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
74
CVEs tracked
10
Critical
26
High
0
In CISA KEV
Severity distribution
MEDIUM30HIGH26CRITICAL10LOW8
Monthly trend
0
1
0
0
0
0
0
0
0
0
1
0
0
1
0
0
0
0
0
0
11
0
24
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Unbound.
- CVE-2026-56444Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration5.9
- CVE-2026-56416Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name4.8
- CVE-2026-55991Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp25.9
- CVE-2026-55990Packet of death for a DNSCrypt misconfigured Unbound5.9
- CVE-2026-55973'dns-error-reporting: yes' leads to stack buffer overflow7.5
- CVE-2026-55717'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash5.9
- CVE-2026-55708Privacy/configuration issue when adding local data in views through 'unbound-control'3.1
- CVE-2026-54478DNS Cookie bypass when combined with proxy-protocol use3.7
- CVE-2026-52863Memory corruption could lead to crash and denial of service5.9
- CVE-2026-50252Possible cache poisoning attack by mapping source port population per thread9.3
- CVE-2026-50251Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush5.3
- CVE-2026-50248BOGUS configured primary hostname accepted for XFR in auth/rpz zones6.5
- CVE-2026-50243'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL3.7
- CVE-2026-50046Possible heap use-after-free in an error path when a DoT forwarded query is jostled out5.9
- CVE-2026-50045'max-global-quota' reset by DNSSEC validation restarts5.3
Product normalization is registry-driven with AI assist and human review. How it works