Logo
vulnerabilityCVE-2026-41292
Name
CVE-2026-41292
Source
NVD ( link)Debian ( link)
Description
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsing long lists of incoming EDNS options. An adversary sending queries with too many EDNS options can hold Unbound threads hostage while they are parsing and creating internal data structures for the options. Coordinated attacks can result in degradation and/or denial of service. Unbound 1.25.1 contains a patch with a fix to limit acceptable incoming EDNS options (100).
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
unbound
Exploitable

Vulnerability Ratings#


6.6
CVSSv4
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.25.1
Not Affected
buildroot
master
1.25.1
Not Affected
openwrt
master
1.25.1-r1
Not Affected
openwrt
openwrt-25.12
1.25.1-r1
Not Affected
yocto
master
1.25.1
Not Affected
yocto
scarthgap
1.19.3
Exploitable