SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-50045

MEDIUM · CVSS 5.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Unbound versions 1.22.0 through 1.25.1 are vulnerable to a flaw that allows a single client query for a deeply nested DNSSEC-signed name to exceed the configured 'max-global-quota', leading to potential amplification attacks. This vulnerability can result in increased upstream traffic, undermining security measures intended to control amplification. Organizations using affected versions of Unbound should prioritize patching to mitigate the risk of abuse and ensure compliance with security configurations.

CVE
CVE-2026-50045
Severity
MEDIUM
CVSS
5.3
EPSS
0.28%

Original NVD Description

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.

Related CVEs

Other vulnerabilities affecting the same vendor(s)