Improper control of a resource through its lifetime in Unbound - CVE-2026-42534
Published: May 20, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper state management in Unbound jostle logic when processing duplicate queries while resolving queries through a slow or malicious authoritative name server. A remote user can send repeated queries for names served by a controlled slow-responding domain name server to cause a denial of service.
Cache and local data response performance remains unaffected. Exploitation requires the resolver to reach its configured query-per-thread limit, and coordinated attacks can degrade resolution into denial of resolution service.