Impact
Unbound versions up to 1.26.0 contain a vulnerability in the TCP/DoT reading procedure that allows an attacker to send a continuous stream of distinct DNS queries over a single connection. This can monopolize a worker process, causing it to block on processing those requests and preventing other clients from receiving timely responses. The weakness is categorized as CWE‑1050 and CWE‑770.
Affected Systems
NLnet Labs Unbound. Versions 1.26.0 and earlier are affected. The issue is resolved in version 1.26.1 and later releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. While the EPSS score is not reported, the absence of a KEV listing suggests no known widespread exploitation at this time. The attack requires the ability to maintain a persistent TCP or DoT connection to the Unbound server and continuously issue unique, uncached queries. If these conditions are met, the attacker can achieve denial of service by exhausting server resources.
OpenCVE Enrichment