OPENSUSE-SU-2026:11930-1

Vulnerability from csaf_opensuse - Published: 2026-09-29 00:00 - Updated: 2026-09-30 11:18
Summary
libunbound8-1.26.1-1.1 on GA media
Severity
Moderate
Notes
Title of the patch: libunbound8-1.26.1-1.1 on GA media
Description of the patch: These are all security issues fixed in the libunbound8-1.26.1-1.1 package on the GA media of openSUSE Tumbleweed.
Patchnames: openSUSE-Tumbleweed-2026-11930
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Affected products
Product Identifier Version Remediation
Unresolved product id: openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64 —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x —
Vendor Fix
Unresolved product id: openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64 —
Vendor Fix
Threats
Impact moderate
Affected products
Recommended 24 products, the same list as for CVE-2026-77860
Threats
Impact moderate
Affected products
Recommended 24 products, the same list as for CVE-2026-77860
Threats
Impact important
Affected products
Recommended 24 products, the same list as for CVE-2026-77860
Threats
Impact moderate
Affected products
Recommended 24 products, the same list as for CVE-2026-77860
Threats
Impact important
Affected products
Recommended 24 products, the same list as for CVE-2026-77860
Threats
Impact important
Affected products
Recommended 24 products, the same list as for CVE-2026-77860
Threats
Impact important
Affected products
Recommended 24 products, the same list as for CVE-2026-77860
Threats
Impact moderate
Affected products
Recommended 24 products, the same list as for CVE-2026-77860
Threats
Impact moderate
References
URL Category
https://www.suse.com/support/security/rating/ external
https://ftp.suse.com/pub/projects/security/csaf/o… self
https://www.suse.com/security/cve/CVE-2026-77860/ self
https://www.suse.com/security/cve/CVE-2026-77955/ self
https://www.suse.com/security/cve/CVE-2026-78227/ self
https://www.suse.com/security/cve/CVE-2026-80225/ self
https://www.suse.com/security/cve/CVE-2026-81634/ self
https://www.suse.com/security/cve/CVE-2026-81642/ self
https://www.suse.com/security/cve/CVE-2026-82717/ self
https://www.suse.com/security/cve/CVE-2026-82720/ self
https://www.suse.com/security/cve/CVE-2026-85501/ self
https://www.suse.com/security/cve/CVE-2026-77860 external
https://bugzilla.suse.com/1280403 external
https://www.suse.com/security/cve/CVE-2026-77955 external
https://bugzilla.suse.com/1280404 external
https://www.suse.com/security/cve/CVE-2026-78227 external
https://bugzilla.suse.com/1280405 external
https://www.suse.com/security/cve/CVE-2026-80225 external
https://bugzilla.suse.com/1280406 external
https://www.suse.com/security/cve/CVE-2026-81634 external
https://bugzilla.suse.com/1280409 external
https://www.suse.com/security/cve/CVE-2026-81642 external
https://bugzilla.suse.com/1280411 external
https://www.suse.com/security/cve/CVE-2026-82717 external
https://bugzilla.suse.com/1280412 external
https://www.suse.com/security/cve/CVE-2026-82720 external
https://bugzilla.suse.com/1280413 external
https://www.suse.com/security/cve/CVE-2026-85501 external
https://bugzilla.suse.com/1280414 external

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "moderate"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "libunbound8-1.26.1-1.1 on GA media",
        "title": "Title of the patch"
      },
      {
        "category": "description",
        "text": "These are all security issues fixed in the libunbound8-1.26.1-1.1 package on the GA media of openSUSE Tumbleweed.",
        "title": "Description of the patch"
      },
      {
        "category": "details",
        "text": "openSUSE-Tumbleweed-2026-11930",
        "title": "Patchnames"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "SUSE ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "self",
        "summary": "URL of this CSAF notice",
        "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2026_11930-1.json"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-77860 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-77860/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-77955 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-77955/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-78227 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-78227/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-80225 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-80225/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-81634 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-81634/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-81642 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-81642/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-82717 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-82717/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-82720 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-82720/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-85501 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-85501/"
      }
    ],
    "title": "libunbound8-1.26.1-1.1 on GA media",
    "tracking": {
      "current_release_date": "2026-09-30T11:18:57Z",
      "generator": {
        "date": "2026-09-29T00:00:00Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf.pl",
          "version": "1"
        }
      },
      "id": "openSUSE-SU-2026:11930-1",
      "initial_release_date": "2026-09-29T00:00:00Z",
      "revision_history": [
        {
          "date": "2026-09-29T00:00:00Z",
          "number": "1",
          "summary": "Current version"
        },
        {
          "date": "2026-09-30T11:18:57Z",
          "number": "2",
          "summary": "unknown changes"
        }
      ],
      "status": "final",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libunbound8-0:1.26.1-1.1.aarch64",
                "product": {
                  "name": "libunbound8-0:1.26.1-1.1.aarch64",
                  "product_id": "libunbound8-0:1.26.1-1.1.aarch64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/libunbound8@1.26.1-1.1?arch=aarch64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-unbound-0:1.26.1-1.1.aarch64",
                "product": {
                  "name": "python3-unbound-0:1.26.1-1.1.aarch64",
                  "product_id": "python3-unbound-0:1.26.1-1.1.aarch64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/python3-unbound@1.26.1-1.1?arch=aarch64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-0:1.26.1-1.1.aarch64",
                "product": {
                  "name": "unbound-0:1.26.1-1.1.aarch64",
                  "product_id": "unbound-0:1.26.1-1.1.aarch64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound@1.26.1-1.1?arch=aarch64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-anchor-0:1.26.1-1.1.aarch64",
                "product": {
                  "name": "unbound-anchor-0:1.26.1-1.1.aarch64",
                  "product_id": "unbound-anchor-0:1.26.1-1.1.aarch64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-anchor@1.26.1-1.1?arch=aarch64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.26.1-1.1.aarch64",
                "product": {
                  "name": "unbound-devel-0:1.26.1-1.1.aarch64",
                  "product_id": "unbound-devel-0:1.26.1-1.1.aarch64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-devel@1.26.1-1.1?arch=aarch64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-munin-0:1.26.1-1.1.aarch64",
                "product": {
                  "name": "unbound-munin-0:1.26.1-1.1.aarch64",
                  "product_id": "unbound-munin-0:1.26.1-1.1.aarch64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-munin@1.26.1-1.1?arch=aarch64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libunbound8-0:1.26.1-1.1.ppc64le",
                "product": {
                  "name": "libunbound8-0:1.26.1-1.1.ppc64le",
                  "product_id": "libunbound8-0:1.26.1-1.1.ppc64le",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/libunbound8@1.26.1-1.1?arch=ppc64le\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-unbound-0:1.26.1-1.1.ppc64le",
                "product": {
                  "name": "python3-unbound-0:1.26.1-1.1.ppc64le",
                  "product_id": "python3-unbound-0:1.26.1-1.1.ppc64le",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/python3-unbound@1.26.1-1.1?arch=ppc64le\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-0:1.26.1-1.1.ppc64le",
                "product": {
                  "name": "unbound-0:1.26.1-1.1.ppc64le",
                  "product_id": "unbound-0:1.26.1-1.1.ppc64le",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound@1.26.1-1.1?arch=ppc64le\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-anchor-0:1.26.1-1.1.ppc64le",
                "product": {
                  "name": "unbound-anchor-0:1.26.1-1.1.ppc64le",
                  "product_id": "unbound-anchor-0:1.26.1-1.1.ppc64le",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-anchor@1.26.1-1.1?arch=ppc64le\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.26.1-1.1.ppc64le",
                "product": {
                  "name": "unbound-devel-0:1.26.1-1.1.ppc64le",
                  "product_id": "unbound-devel-0:1.26.1-1.1.ppc64le",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-devel@1.26.1-1.1?arch=ppc64le\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-munin-0:1.26.1-1.1.ppc64le",
                "product": {
                  "name": "unbound-munin-0:1.26.1-1.1.ppc64le",
                  "product_id": "unbound-munin-0:1.26.1-1.1.ppc64le",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-munin@1.26.1-1.1?arch=ppc64le\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "ppc64le"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libunbound8-0:1.26.1-1.1.s390x",
                "product": {
                  "name": "libunbound8-0:1.26.1-1.1.s390x",
                  "product_id": "libunbound8-0:1.26.1-1.1.s390x",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/libunbound8@1.26.1-1.1?arch=s390x\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-unbound-0:1.26.1-1.1.s390x",
                "product": {
                  "name": "python3-unbound-0:1.26.1-1.1.s390x",
                  "product_id": "python3-unbound-0:1.26.1-1.1.s390x",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/python3-unbound@1.26.1-1.1?arch=s390x\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-0:1.26.1-1.1.s390x",
                "product": {
                  "name": "unbound-0:1.26.1-1.1.s390x",
                  "product_id": "unbound-0:1.26.1-1.1.s390x",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound@1.26.1-1.1?arch=s390x\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-anchor-0:1.26.1-1.1.s390x",
                "product": {
                  "name": "unbound-anchor-0:1.26.1-1.1.s390x",
                  "product_id": "unbound-anchor-0:1.26.1-1.1.s390x",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-anchor@1.26.1-1.1?arch=s390x\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.26.1-1.1.s390x",
                "product": {
                  "name": "unbound-devel-0:1.26.1-1.1.s390x",
                  "product_id": "unbound-devel-0:1.26.1-1.1.s390x",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-devel@1.26.1-1.1?arch=s390x\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-munin-0:1.26.1-1.1.s390x",
                "product": {
                  "name": "unbound-munin-0:1.26.1-1.1.s390x",
                  "product_id": "unbound-munin-0:1.26.1-1.1.s390x",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-munin@1.26.1-1.1?arch=s390x\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "s390x"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libunbound8-0:1.26.1-1.1.x86_64",
                "product": {
                  "name": "libunbound8-0:1.26.1-1.1.x86_64",
                  "product_id": "libunbound8-0:1.26.1-1.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/libunbound8@1.26.1-1.1?arch=x86_64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "python3-unbound-0:1.26.1-1.1.x86_64",
                "product": {
                  "name": "python3-unbound-0:1.26.1-1.1.x86_64",
                  "product_id": "python3-unbound-0:1.26.1-1.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/python3-unbound@1.26.1-1.1?arch=x86_64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-0:1.26.1-1.1.x86_64",
                "product": {
                  "name": "unbound-0:1.26.1-1.1.x86_64",
                  "product_id": "unbound-0:1.26.1-1.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound@1.26.1-1.1?arch=x86_64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-anchor-0:1.26.1-1.1.x86_64",
                "product": {
                  "name": "unbound-anchor-0:1.26.1-1.1.x86_64",
                  "product_id": "unbound-anchor-0:1.26.1-1.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-anchor@1.26.1-1.1?arch=x86_64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-devel-0:1.26.1-1.1.x86_64",
                "product": {
                  "name": "unbound-devel-0:1.26.1-1.1.x86_64",
                  "product_id": "unbound-devel-0:1.26.1-1.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-devel@1.26.1-1.1?arch=x86_64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "unbound-munin-0:1.26.1-1.1.x86_64",
                "product": {
                  "name": "unbound-munin-0:1.26.1-1.1.x86_64",
                  "product_id": "unbound-munin-0:1.26.1-1.1.x86_64",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nlnetlabs:unbound:1.26.1:*:*:*:*:*:*:*",
                    "purl": "pkg:rpm/suse/unbound-munin@1.26.1-1.1?arch=x86_64\u0026upstream=unbound-0:1.26.1-1.1.src.rpm"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "openSUSE Tumbleweed",
                "product": {
                  "name": "openSUSE Tumbleweed",
                  "product_id": "openSUSE Tumbleweed",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:opensuse:tumbleweed"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound8-0:1.26.1-1.1.aarch64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64"
        },
        "product_reference": "libunbound8-0:1.26.1-1.1.aarch64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound8-0:1.26.1-1.1.ppc64le as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le"
        },
        "product_reference": "libunbound8-0:1.26.1-1.1.ppc64le",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound8-0:1.26.1-1.1.s390x as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x"
        },
        "product_reference": "libunbound8-0:1.26.1-1.1.s390x",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libunbound8-0:1.26.1-1.1.x86_64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64"
        },
        "product_reference": "libunbound8-0:1.26.1-1.1.x86_64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-unbound-0:1.26.1-1.1.aarch64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64"
        },
        "product_reference": "python3-unbound-0:1.26.1-1.1.aarch64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-unbound-0:1.26.1-1.1.ppc64le as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le"
        },
        "product_reference": "python3-unbound-0:1.26.1-1.1.ppc64le",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-unbound-0:1.26.1-1.1.s390x as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x"
        },
        "product_reference": "python3-unbound-0:1.26.1-1.1.s390x",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "python3-unbound-0:1.26.1-1.1.x86_64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64"
        },
        "product_reference": "python3-unbound-0:1.26.1-1.1.x86_64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.26.1-1.1.aarch64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64"
        },
        "product_reference": "unbound-0:1.26.1-1.1.aarch64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.26.1-1.1.ppc64le as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le"
        },
        "product_reference": "unbound-0:1.26.1-1.1.ppc64le",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.26.1-1.1.s390x as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x"
        },
        "product_reference": "unbound-0:1.26.1-1.1.s390x",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-0:1.26.1-1.1.x86_64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64"
        },
        "product_reference": "unbound-0:1.26.1-1.1.x86_64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-anchor-0:1.26.1-1.1.aarch64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64"
        },
        "product_reference": "unbound-anchor-0:1.26.1-1.1.aarch64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-anchor-0:1.26.1-1.1.ppc64le as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le"
        },
        "product_reference": "unbound-anchor-0:1.26.1-1.1.ppc64le",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-anchor-0:1.26.1-1.1.s390x as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x"
        },
        "product_reference": "unbound-anchor-0:1.26.1-1.1.s390x",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-anchor-0:1.26.1-1.1.x86_64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64"
        },
        "product_reference": "unbound-anchor-0:1.26.1-1.1.x86_64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.26.1-1.1.aarch64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64"
        },
        "product_reference": "unbound-devel-0:1.26.1-1.1.aarch64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.26.1-1.1.ppc64le as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le"
        },
        "product_reference": "unbound-devel-0:1.26.1-1.1.ppc64le",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.26.1-1.1.s390x as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x"
        },
        "product_reference": "unbound-devel-0:1.26.1-1.1.s390x",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-devel-0:1.26.1-1.1.x86_64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64"
        },
        "product_reference": "unbound-devel-0:1.26.1-1.1.x86_64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-munin-0:1.26.1-1.1.aarch64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64"
        },
        "product_reference": "unbound-munin-0:1.26.1-1.1.aarch64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-munin-0:1.26.1-1.1.ppc64le as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le"
        },
        "product_reference": "unbound-munin-0:1.26.1-1.1.ppc64le",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-munin-0:1.26.1-1.1.s390x as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x"
        },
        "product_reference": "unbound-munin-0:1.26.1-1.1.s390x",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "unbound-munin-0:1.26.1-1.1.x86_64 as component of openSUSE Tumbleweed",
          "product_id": "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        },
        "product_reference": "unbound-munin-0:1.26.1-1.1.x86_64",
        "relates_to_product_reference": "openSUSE Tumbleweed"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-77860",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-77860"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the \u0027serve-expired\u0027 code path can cause a double decrement on the \u0027wait-limit\u0027 counter per client IP essentially bypassing one of the counter measures that was introduced for DNSBomb (CVE-2024-33655). A malicious actor can exploit this by controlling an authoritative zone with short TTL, so cached entries expire quickly. Each \u0027slow\u0027 query, one the attacker\u0027s authoritative never answers, is followed by one query for an expired cached name, which is answered immediately via the \u0027serve-expired\u0027 path and decrements the counter twice. This second query was named \u0027pump\u0027. By alternating slow queries and pumps, the attacker keeps the per-client counter at or below the configured \u0027wait-limit\u0027 indefinitely, and can hold an arbitrary number of pending queries from a single source IP, up to the global mesh quota (num-queries-per-thread); eventually bypassing one of the counter measures introduced for DNSBomb (CVE-2024-33655). This vulnerability is present on the \u0027serve-expired\u0027 code path.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-77860",
          "url": "https://www.suse.com/security/cve/CVE-2026-77860"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280403 for CVE-2026-77860",
          "url": "https://bugzilla.suse.com/1280403"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-29T00:00:00Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-77860"
    },
    {
      "cve": "CVE-2026-77955",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-77955"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-77955",
          "url": "https://www.suse.com/security/cve/CVE-2026-77955"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280404 for CVE-2026-77955",
          "url": "https://bugzilla.suse.com/1280404"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-29T00:00:00Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-77955"
    },
    {
      "cve": "CVE-2026-78227",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-78227"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with \u0027--with-libngtcp2\u0027. Each DoQ stream owns an output buffer that holds the DNS response. ngtcp2\u0027s retransmission buffer keeps a shallow pointer into the output buffer for as long as a STREAM frame may be resent. On a client RESET_STREAM, the output buffer is freed but ngtcp2 still holds the matching retransmission entries. The next PTO timeout makes ngtcp2 re-encode the STREAM frame and copy from the freed buffer. A malicious actor that can query Unbound over DoQ and that withholds ACKs, sends RESET_STREAM, and waits for PTO, reaches this use-after-free with no privilege. This leads to retransmissions against freed memory and eventually an abnormal server exit under a 20-query spray.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-78227",
          "url": "https://www.suse.com/security/cve/CVE-2026-78227"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280405 for CVE-2026-78227",
          "url": "https://bugzilla.suse.com/1280405"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-29T00:00:00Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-78227"
    },
    {
      "cve": "CVE-2026-80225",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-80225"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker\u0027s entire event loop for as long as its writes stay ahead of the drain.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-80225",
          "url": "https://www.suse.com/security/cve/CVE-2026-80225"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280406 for CVE-2026-80225",
          "url": "https://bugzilla.suse.com/1280406"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-29T00:00:00Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-80225"
    },
    {
      "cve": "CVE-2026-81634",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-81634"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-81634",
          "url": "https://www.suse.com/security/cve/CVE-2026-81634"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280409 for CVE-2026-81634",
          "url": "https://bugzilla.suse.com/1280409"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-29T00:00:00Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-81634"
    },
    {
      "cve": "CVE-2026-81642",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-81642"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-81642",
          "url": "https://www.suse.com/security/cve/CVE-2026-81642"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280411 for CVE-2026-81642",
          "url": "https://bugzilla.suse.com/1280411"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-29T00:00:00Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-81642"
    },
    {
      "cve": "CVE-2026-82717",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-82717"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Coupled with a compression pointer that points to the overwritten value and invalidates the domain name, it leads to an error path that does not properly move the buffer position and allows for the heap buffer overflow. Since this is heavily reliant on heap memory layout, results are memory corruption that eventually leads to a crash and under specific systems and compilation options remote code execution.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-82717",
          "url": "https://www.suse.com/security/cve/CVE-2026-82717"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280412 for CVE-2026-82717",
          "url": "https://bugzilla.suse.com/1280412"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-29T00:00:00Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-82717"
    },
    {
      "cve": "CVE-2026-82720",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-82720"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with \u0027--with-libnghttp2\u0027. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If the prerequisites are satisfied (possible RPZ drop or heavy client traffic), a malicious actor can trigger the vulnerability with a single DoH connection and the appropriate traffic. Impact is limited as the reads are not user controlled and the use-after-free leads to early returns. However, a hardened allocator can catch the use-after-free and controllably terminate the process resulting to denial of service.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-82720",
          "url": "https://www.suse.com/security/cve/CVE-2026-82720"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280413 for CVE-2026-82720",
          "url": "https://bugzilla.suse.com/1280413"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-29T00:00:00Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-82720"
    },
    {
      "cve": "CVE-2026-85501",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-85501"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the term \u0027ReTrap\u0027. These result in degradation of service when malicious zones are used to serve the algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to some of them. TagTrap, where  the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY and DS records from the root zone downward. For deeply nested domains, this results in significant computational overhead. NsecTrap, where  responses with excessive invalid NSEC records compel the resolver to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL section as well. This can be exploited to waste validation resources by malicious users.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
          "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-85501",
          "url": "https://www.suse.com/security/cve/CVE-2026-85501"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1280414 for CVE-2026-85501",
          "url": "https://bugzilla.suse.com/1280414"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
            "version": "3.1"
          },
          "products": [
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:libunbound8-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:python3-unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-anchor-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-devel-0:1.26.1-1.1.x86_64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.aarch64",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.ppc64le",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.s390x",
            "openSUSE Tumbleweed:unbound-munin-0:1.26.1-1.1.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-29T00:00:00Z",
          "details": "moderate"
        }
      ],
      "title": "CVE-2026-85501"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…