LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-50252

nlnetlabs · unbound

Published
CVSS9.3
Severitycritical
WeaknessCWE-349
ExploitedNot in CISA KEV

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

Description

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (by default), it meets these conditions, making it vulnerable for DNS cache poisoning attacks. Upon s

References

← Back to the CVE Tracker

Our coverage of CVE-2026-50252

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-50252.