CVE-2026-44390: CWE-407: Inefficient Algorithmic Complexity in NLnet Labs Unbound
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the compression tree lookup failure and eventually not increment the compression counter for those operations. Unbound 1.25.1 contains a patch with a fix that increments the compression counter regardless of the compression tree lookup. This is a complement fix to CVE-2024-8508.
AI Analysis
Technical Summary
CVE-2026-44390 describes an inefficient algorithmic complexity vulnerability in NLnet Labs Unbound DNS resolver up to version 1.25.0. When Unbound handles replies containing very large RRsets that require name compression, specially crafted malicious responses with records that do not share a suffix above the root cause Unbound to enter an unbounded processing loop. This happens because the compression counter, introduced in version 1.21.1 to limit compression operations, is not incremented when the compression tree lookup fails due to lack of shared suffixes. As a result, Unbound can spend excessive CPU time compressing names before replying, leading to degraded performance and denial of service. The issue is fixed in version 1.25.1 by ensuring the compression counter increments regardless of compression tree lookup success. This fix complements a previous related fix (CVE-2024-8508). The vulnerability is rated medium severity with a CVSS 4.0 score of 6.9. Red Hat has issued an important security advisory providing patched packages for affected Red Hat Enterprise Linux 10 variants.
Potential Impact
The vulnerability allows an unauthenticated remote attacker to cause a denial of service by sending malicious DNS responses with very large RRsets that trigger excessive CPU consumption in Unbound during name compression. This can degrade resolver performance and potentially lock the CPU until the packet processing completes, impacting availability of DNS resolution services. There is no indication of privilege escalation, data disclosure, or integrity impact. The CVSS 4.0 base score of 6.9 reflects a medium severity denial of service impact with network attack vector and low attack complexity.
Mitigation Recommendations
A fix is available in Unbound version 1.25.1 that corrects the compression counter behavior to prevent unbounded CPU consumption. Users should upgrade to version 1.25.1 or later. Red Hat has released patched packages for Red Hat Enterprise Linux 10 and related variants; applying these updates will remediate the vulnerability. No other mitigations or workarounds are specified. Patch status is confirmed by the vendor advisory. Users should consult the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-44390 and apply the recommended updates promptly.
CVE-2026-44390: CWE-407: Inefficient Algorithmic Complexity in NLnet Labs Unbound
Description
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the compression tree lookup failure and eventually not increment the compression counter for those operations. Unbound 1.25.1 contains a patch with a fix that increments the compression counter regardless of the compression tree lookup. This is a complement fix to CVE-2024-8508.
CVSS v4.0
Score 6.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-44390 describes an inefficient algorithmic complexity vulnerability in NLnet Labs Unbound DNS resolver up to version 1.25.0. When Unbound handles replies containing very large RRsets that require name compression, specially crafted malicious responses with records that do not share a suffix above the root cause Unbound to enter an unbounded processing loop. This happens because the compression counter, introduced in version 1.21.1 to limit compression operations, is not incremented when the compression tree lookup fails due to lack of shared suffixes. As a result, Unbound can spend excessive CPU time compressing names before replying, leading to degraded performance and denial of service. The issue is fixed in version 1.25.1 by ensuring the compression counter increments regardless of compression tree lookup success. This fix complements a previous related fix (CVE-2024-8508). The vulnerability is rated medium severity with a CVSS 4.0 score of 6.9. Red Hat has issued an important security advisory providing patched packages for affected Red Hat Enterprise Linux 10 variants.
Potential Impact
The vulnerability allows an unauthenticated remote attacker to cause a denial of service by sending malicious DNS responses with very large RRsets that trigger excessive CPU consumption in Unbound during name compression. This can degrade resolver performance and potentially lock the CPU until the packet processing completes, impacting availability of DNS resolution services. There is no indication of privilege escalation, data disclosure, or integrity impact. The CVSS 4.0 base score of 6.9 reflects a medium severity denial of service impact with network attack vector and low attack complexity.
Mitigation Recommendations
A fix is available in Unbound version 1.25.1 that corrects the compression counter behavior to prevent unbounded CPU consumption. Users should upgrade to version 1.25.1 or later. Red Hat has released patched packages for Red Hat Enterprise Linux 10 and related variants; applying these updates will remediate the vulnerability. No other mitigations or workarounds are specified. Patch status is confirmed by the vendor advisory. Users should consult the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-44390 and apply the recommended updates promptly.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- NLnet Labs
- Date Reserved
- 2026-05-07T10:07:51.828Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-44390","vendor":"Red Hat"}]
Threat ID: 6a0d8700ba1db4736270eed7
Added to database: 05/20/2026, 10:03:44 UTC
Last enriched: 07/30/2026, 21:57:55 UTC
Last updated: 07/31/2026, 21:26:44 UTC
Views: 86
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.