VDB

CVE-2026-42944

CVE-2026-42944 PUBLISHED CVSS 7.5 HIGH

NLnet Labs  has disclosed several vulnerabilities affecting Unbound DNS resolver which could result in denial-of-service (DoS). CVE-2026-33278 is a critical vulnerability with a CVSS score 9.8 affecting Unbound 1.19.1 through 1.25.0. This vulnerability exists in the DNSSEC validator during NSEC3 validation handling and is caused by an incorrect deep-copy operation. A crafted DNSSEC response can trigger access to freed memory, leading to crashes or possible remote code execution. CVE-2026-42944 is heap overflow vulnerability, in EDNS reply packet encoding, affecting Unbound versions 1.14.0 through 1.25.0. The flaw is caused by incorrect EDNS size calculations when handling multiple NSID, DNS Cookie, or EDNS Padding options. A remote unauthenticated attacker can trigger the issue by sending specially crafted DNS queries. Exploitation can crash the service, resulting in a denial-of-service condition. CVE-2026-42959 is denial-of-service vulnerability existing in Unbound up to version 1.25.0 within the DNSSEC validator. This issue  arises from incorrect counter usage when calculating write offsets for ADDITIONAL section RRsets during chase-reply construction. DNAME duplication and AUTHORITY filtering can create uninitialized array slots, leading to invalid memory references. An attacker controlling a DNSSEC-signed domain can trigger the bug with a single crafted query, resulting in an immediate process crash.

EPSS 0.06% · 18.8th percentile

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.06%
18.8th percentile

Affected Products

VendorProductVersions
UnboundUnbound DNS resolver, versions up to and including 1.25.0.

Timeline

  • May 20, 2026 EPSS Score
  • May 20, 2026 CVE Published
  • May 20, 2026 PoC Published
  • May 20, 2026 PoC Published
  • May 20, 2026 CVE Updated
  • May 21, 2026 EPSS Score
  • May 21, 2026 Coalition ESS Score
  • May 21, 2026 Security Advisory
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›