CVE Vulnerabilities

CVE-2026-77860

Multiple Operations on Resource in Single-Operation Context

Published: Sep 16, 2026 | Modified: Sep 23, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the serve-expired code path can cause a double decrement on the wait-limit counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A malicious actor can exploit this by controlling an authoritative zone with short TTL, so cached entries expire quickly. Each slow query, one the attackers authoritative never answers, is followed by one query for an expired cached name, which is answered immediately via the serve-expired path and decrements the counter twice. This second query was named pump. By alternating slow queries and pumps, the attacker keeps the per-client counter at or below the configured wait-limit indefinitely, and can hold an arbitrary number of pending queries from a single source IP, up to the global mesh quota (num-queries-per-thread); eventually bypassing one of the counter measures introduced for DNSBomb (CVE-2024-33655). This vulnerability is present on the serve-expired code path.

Weakness

The product performs the same operation on a resource two or more times, when the operation should only be applied once.

Affected Software

NameVendorStart VersionEnd Version
UnboundNlnetlabs1.20.0 (including)1.26.1 (excluding)
Red Hat Hardened ImagesRedHatunbound-main-1.26.1-1.hum1*
UnboundUbuntuupstream*

References