Impact
A single client DNS query for a deeply nested name under a DNSSEC‑signed parent can trigger Unbound to issue more upstream packets than the configured max-global-quota, thereby violating the intended restriction on upstream amplification. Consequently, an attacker could coerce the resolver into sending additional traffic to upstream servers, potentially amplifying network impact and weakening the controlled traffic profile.
Affected Systems
NLnet Labs Unbound versions 1.22.0 through 1.25.1 are impacted; the problem is resolved in 1.25.2 and later releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA KEV, so known exploitation data is lacking. The likely attack vector would be a client sending a specially crafted DNS query, causing the resolver to exceed its upstream quota and generate amplification traffic. This represents a potential DoS or network abuse scenario, but the low EPSS score and lack of public exploitation reports suggest the risk is low to moderate.
OpenCVE Enrichment