Off-by-one in Unbound - CVE-2026-44687
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an off-by-one error in harden-below-nxdomain logic when processing queries for the intermediate label between a configured stub or forward zone apex and its DNSSEC parent zone. A remote attacker can send a specially crafted query to cause a denial of service.
The issue can prevent the configured stub or forward upstream from being contacted by causing a DNSSEC-secure NXDOMAIN answer from the public parent to shadow the zone.