๐Ÿ” CVE Alert

CVE-2026-50045

MEDIUM 5.3

'max-global-quota' reset by DNSSEC validation restarts

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.

CWE CWE-406
Vendor nlnet labs
Product unbound
Published Jul 22, 2026
Stay Ahead of the Next One

Get instant alerts for nlnet labs unbound

Be the first to know when new medium vulnerabilities affecting nlnet labs unbound are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

NLnet Labs / Unbound
1.22.0 < 1.25.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
nlnetlabs.nl: https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50045.txt

Credits

Kunjie Shang (University of Science and Technology of China)