<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 16:07:19 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-339390</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-339390</link>
      <description>EUVD-2026-339390</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-339390</guid>
    </item>
    <item>
      <title>fkie_cve-2026-50251</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-50251</link>
      <description>&lt;p&gt;In NLnet Labs Unbound up to and including version 1.25.1, when &amp;#39;unwanted-reply-threshold&amp;#39; is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured &amp;#39;unwanted-reply-threshold&amp;#39; that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of &amp;#39;unwanted-reply-threshold&amp;#39; to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound&amp;#39;s own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In NLnet Labs Unbound up to and including version 1.25.1, when &amp;#39;unwanted-reply-threshold&amp;#39; is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured &amp;#39;unwanted-reply-threshold&amp;#39; that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of &amp;#39;unwanted-reply-threshold&amp;#39; to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound&amp;#39;s own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-50251</guid>
    </item>
    <item>
      <title>GHSA-rj42-r8f9-w75j</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rj42-r8f9-w75j</link>
      <description>&lt;p&gt;In NLnet Labs Unbound up to and including version 1.25.1, when &amp;#39;unwanted-reply-threshold&amp;#39; is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured &amp;#39;unwanted-reply-threshold&amp;#39; that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of &amp;#39;unwanted-reply-threshold&amp;#39; to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound&amp;#39;s own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In NLnet Labs Unbound up to and including version 1.25.1, when &amp;#39;unwanted-reply-threshold&amp;#39; is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured &amp;#39;unwanted-reply-threshold&amp;#39; that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of &amp;#39;unwanted-reply-threshold&amp;#39; to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound&amp;#39;s own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rj42-r8f9-w75j</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-50251 — Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-50251</link>
      <description>msrc_CVE-2026-50251</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-50251</guid>
    </item>
    <item>
      <title>OESA-2026-3333 — unbound security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3333</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: unbound&lt;/p&gt;
&lt;p&gt;Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards. To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows. Unbound is a totally free, open source software under the BSD license. It doesn&amp;amp;amp;apos;t make custom builds or provide specific features to paying customers only.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with &amp;amp;apos;unwanted-reply-threshold&amp;amp;apos;, could eventually be abruptly terminated if the threshold is reached and libunbound needs to call &amp;amp;apos;libworker_alloc_cleanup&amp;amp;apos; since the function is absent from the function call allow list. When an application using libunbound sets &amp;amp;apos;unwanted-reply-threshold&amp;amp;apos; to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the &amp;amp;apos;libworker_alloc_cleanup&amp;amp;apos; will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function &amp;amp;apos;worker_alloc_cleanup&amp;amp;apos; is registed in the allow list and proceeds to…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: unbound&lt;/p&gt;
&lt;p&gt;Unbound is a validating, recursive, caching DNS resolver. It is designed to be fast and lean and incorporates modern features based on open standards. To help increase online privacy, Unbound supports DNS-over-TLS which allows clients to encrypt their communication. Unbound is available for most platforms such as FreeBSD, OpenBSD, NetBSD, MacOS, Linux and Microsoft Windows. Unbound is a totally free, open source software under the BSD license. It doesn&amp;amp;amp;apos;t make custom builds or provide specific features to paying customers only.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with &amp;amp;apos;unwanted-reply-threshold&amp;amp;apos;, could eventually be abruptly terminated if the threshold is reached and libunbound needs to call &amp;amp;apos;libworker_alloc_cleanup&amp;amp;apos; since the function is absent from the function call allow list. When an application using libunbound sets &amp;amp;apos;unwanted-reply-threshold&amp;amp;apos; to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the &amp;amp;apos;libworker_alloc_cleanup&amp;amp;apos; will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function &amp;amp;apos;worker_alloc_cleanup&amp;amp;apos; is registed in the allow list and proceeds to…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3333</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11380-1 — libunbound8-1.25.2-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11380-1</link>
      <description>&lt;p&gt;libunbound8-1.25.2-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libunbound8-1.25.2-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11380-1</guid>
    </item>
    <item>
      <title>RHSA-2026:43588 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:43588</link>
      <description>&lt;p&gt;unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length unbound: Unbound: Denial of Service via crafted DNSCrypt query unbound: Unbound: Denial of Service via terminated DNS-over-QUIC queries unbound: Unbound: DNS cache integrity issue unbound: Unbound: Denial of Service due to &amp;#39;harden-below-nxdomain&amp;#39; logic bypass unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes unbound: Unbound: Information disclosure via DNSSEC wildcard replay unbound: Unbound: Denial of Service via DNSSEC query amplification bypass unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling unbound: Unbound: Insecure DNS redirection via spoofed DNS answers unbound: Unbound: DNS response policy replacement via hostname spoofing unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records unbound: Unbound: DNS cache poisoning via UDP source port predictability unbound: Unbound: Denial of service due to memory corruption under specific configurations. unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation unbound: Unbound: Information disclosure due to local policy bypass via unbound-control unbound: Unbound: Denial of Service via crafted DNS responses with expired records unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option unbound:…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length unbound: Unbound: Denial of Service via crafted DNSCrypt query unbound: Unbound: Denial of Service via terminated DNS-over-QUIC queries unbound: Unbound: DNS cache integrity issue unbound: Unbound: Denial of Service due to &amp;#39;harden-below-nxdomain&amp;#39; logic bypass unbound: Unbound: Cache poisoning via insufficient RRSIG.Labels validation and premature cache writes unbound: Unbound: Information disclosure via DNSSEC wildcard replay unbound: Unbound: Denial of Service via DNSSEC query amplification bypass unbound: Unbound: Denial of Service due to freed pointer dereference in DNS-over-TLS handling unbound: Unbound: Insecure DNS redirection via spoofed DNS answers unbound: Unbound: DNS response policy replacement via hostname spoofing unbound: NLnet Labs Unbound: Denial of Service via crafted DNS glue records unbound: Unbound: DNS cache poisoning via UDP source port predictability unbound: Unbound: Denial of service due to memory corruption under specific configurations. unbound: Unbound: DNS Cookie security bypass via incorrect server cookie calculation unbound: Unbound: Information disclosure due to local policy bypass via unbound-control unbound: Unbound: Denial of Service via crafted DNS responses with expired records unbound: Unbound: Denial of Service via malformed EDNS Report-Channel option unbound:…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:43588</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23050-1 — Security update for unbound</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23050-1</link>
      <description>&lt;p&gt;Security update for unbound&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for unbound&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23050-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-50251</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50251</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:18.04:LTS: unbound, Ubuntu:Pro:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound, Ubuntu:24.04:LTS: unbound, Ubuntu:26.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound up to and including version 1.25.1, when &amp;#39;unwanted-reply-threshold&amp;#39; is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured &amp;#39;unwanted-reply-threshold&amp;#39; that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of &amp;#39;unwanted-reply-threshold&amp;#39; to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound&amp;#39;s own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: unbound, Ubuntu:Pro:16.04:LTS: unbound, Ubuntu:Pro:18.04:LTS: unbound, Ubuntu:Pro:20.04:LTS: unbound, Ubuntu:22.04:LTS: unbound, Ubuntu:24.04:LTS: unbound, Ubuntu:26.04:LTS: unbound&lt;/p&gt;
&lt;p&gt;In NLnet Labs Unbound up to and including version 1.25.1, when &amp;#39;unwanted-reply-threshold&amp;#39; is enabled (set to any value greater than zero), glue records of 0.0.0.0/::0 can short-circuit Unbound, on systems that can direct such traffic, by issuing DNS queries and receiving seemingly unwanted replies since the remote IP does not match the original source IP of 0.0.0.0/::0. This behavior keeps on looping for the glue records and pushing the counter to the configured &amp;#39;unwanted-reply-threshold&amp;#39; that triggers a defensive cache clear. A malicious actor who controls a delegation that returns in-bailiwick glue of 0.0.0.0/::0 can drive the counter to the limit of &amp;#39;unwanted-reply-threshold&amp;#39; to the threshold and trigger a cache clean of the message and rrset caches; at will, indefinitely, without sending a single spoofed packet. The iterator uses the 0.0.0.0/::0 glue, and a system that can route this (e.g., Linux kernel routes the datagram over loopback), Unbound&amp;#39;s own listener answers from 127.0.0.1. Because of the mismatch of 0.0.0.0 and 127.0.0.1, in this example, Unbound accounts the reply as an unwanted (probably spoofed) answer. The counter resets to zero on every cache flush, so the attack loops forever.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-50251</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2492 — Unbound: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2492</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Unbound ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Daten zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Unbound ausnutzen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Daten zu manipulieren, und um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2492</guid>
    </item>
  </channel>
</rss>
