Improper handling of exceptional conditions in Unbound - CVE-2026-50251
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of unwanted replies in the iterator when processing in-bailiwick glue records of 0.0.0.0/::0 with 'unwanted-reply-threshold' enabled. A remote attacker can control a delegation that returns crafted glue records to cause a denial of service.
The issue can repeatedly trigger defensive clearing of the message and rrset caches, and does not require sending spoofed packets.