Resource exhaustion in Unbound - CVE-2026-41292
Published: May 20, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in EDNS option parsing when handling queries with long lists of EDNS options. A remote attacker can send specially crafted queries with too many EDNS options to cause a denial of service.
Coordinated attacks can degrade service by tying up Unbound threads while internal data structures for the options are being created.