CyberRota Analysis
AI-GeneratedUnbound versions 1.22.0 through 1.25.1 are vulnerable to a flaw that allows a single client query for a deeply nested DNSSEC-signed name to exceed the configured 'max-global-quota', leading to potential amplification attacks. This vulnerability can result in increased upstream traffic, undermining security measures intended to control amplification. Organizations using affected versions of Unbound should prioritize patching to mitigate the risk of abuse and ensure compliance with security configurations.
Original NVD Description
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.
Related CVEs
Other vulnerabilities affecting the same vendor(s)