Resource exhaustion in Unbound - CVE-2026-80225
Published: September 16, 2026 / Updated: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in Unbound's TCP/DoT reading procedure when processing a sustained stream of distinct uncached names over a TCP/DoT connection. A remote attacker can stream distinct uncached names at a sustained rate to cause a denial of service.
Affected software
Fedora
unbound
How to mitigate CVE-2026-80225
unbound - addressed in versions 1.26.1-1.fc43, 1.26.1-1.fc44, 1.26.1-1.fc45