SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-50046

MEDIUM · CVSS 5.9 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Unbound versions 1.15.0 through 1.25.1 are vulnerable to a denial-of-service attack due to improper handling of TLS server names during DNS-over-TLS (DoT) queries. When specific conditions are met, such as a misconfigured stub/forward zone and transient connectivity failures, a malicious actor can exploit this flaw to crash the daemon. Organizations using affected versions of Unbound with DoT configurations should prioritize remediation to prevent potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-50046
Severity
MEDIUM
CVSS
5.9
EPSS
0.24%

Original NVD Description

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.

Related CVEs

Other vulnerabilities affecting the same vendor(s)