Allocation of Resources Without Limits or Throttling in Unbound - CVE-2026-50045
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass upstream amplification traffic limits.
The vulnerability exists due to improper resource management in the DNSSEC validator when processing a single client query for a deeply nested name under a DNSSEC-signed parent. A remote attacker can send a specially crafted query to bypass upstream amplification traffic limits.