CVE Vulnerabilities

CVE-2026-50045

Insufficient Control of Network Message Volume (Network Amplification)

Published: Jul 22, 2026 | Modified: Jul 22, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured max-global-quota. This effectively bypasses a security configuration that limits upstream amplification traffic.

Weakness

The product does not sufficiently monitor or control transmitted network traffic volume, so that an actor can cause the product to transmit more traffic than should be allowed for that actor.

Affected Software

NameVendorStart VersionEnd Version
UnboundUbuntuupstream*

Potential Mitigations

References