CVE-2026-50045
MEDIUMDescription
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.
Is your site exposed to CVE-2026-50045?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| nlnetlabs | unbound |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-50045? +
How severe is CVE-2026-50045? +
What products are affected by CVE-2026-50045? +
How do I check if I'm vulnerable to CVE-2026-50045? +
Related Vulnerabilities
Possible External Service Interaction attack in iManager has been discovered in OpenText™ iManager 3.2.6.0000.
QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards RECONNECT_REQUEST packets …
An issue was discovered in Technitium through 11.0.2. The forwarding mode enables attackers to create a query loop using Technitium …
IBM MQ 9.2 LTS, 9.3 LTS, and 9.3 CD Internet Pass-Thru could allow a remote user to cause a denial …
An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more than other …
Technitium 11.5.3 allows remote attackers to cause a denial of service (bandwidth amplification) because the DNSBomb manipulation causes accumulation of …