CVE-2026-41292
MEDIUM EPSS 34.5%
Published May 20, 20261mo ago · Modified Jun 17, 20261w ago
6.6 CVSS 4.0
Published May 20, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago
Description
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X
Threat Intelligence
EPSS Exploit Probability
34.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 2
CWE-407
CWE-770
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| nlnetlabs | unbound | * | <1.25.1 |
References 1
- nlnetlabs.nl https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-41292.txt
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.