Input validation error in Unbound - CVE-2026-54478
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass DNS Cookie source validation.
The vulnerability exists due to improper input validation in DNS server cookie hash calculations on proxy-protocol-port interfaces when handling PROXYv2-declared client addresses with answer-cookie enabled. A remote attacker can obtain a valid server cookie through a proxy and replay it using a spoofed source to bypass DNS Cookie source validation.
Exploitation requires a UDP deployment using proxy protocol on the front end with answer-cookie enabled.