Improper access control in Unbound - CVE-2026-44621
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper access control in the libworker_alloc_cleanup function call allow list in libunbound when processing enough wrong-transaction-ID UDP replies to cross the unwanted-reply-threshold. A remote attacker can send crafted UDP replies to cause a denial of service.
Only applications using libunbound with 'unwanted-reply-threshold' set to a non-zero value are vulnerable. Unbound itself is not affected.