Inefficient Algorithmic Complexity in Unbound - CVE-2026-85501

 

Inefficient Algorithmic Complexity in Unbound - CVE-2026-85501

Published: September 16, 2026 / Updated: September 19, 2026


Vulnerability identifier: #VU150196
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-85501
CWE-ID: CWE-407
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to inefficient algorithmic complexity in the DNSSEC validator's Zone, Algo, KeyTag matching mechanism when processing DNS responses containing numerous mismatched DNSKEY, RRSIG, and DS records. A remote attacker can provide a crafted DNS response to cause a denial of service.


Affected software

Unbound
Fedora
unbound

How to mitigate CVE-2026-85501

Install security update from vendor's website.

Unbound - update to 1.26.1
unbound - addressed in versions 1.26.1-1.fc43, 1.26.1-1.fc44, 1.26.1-1.fc45

External References

Related Security Bulletins