Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.6%top 53%

CVE-2026-44390: CWE-407: Inefficient Algorithmic Complexity in NLnet Labs Unbound

0
Medium
VulnerabilityCVE-2026-44390cvecve-2026-44390cwe-407
Published: 05/20/2026 (05/20/2026, 09:21:24 UTC)
Source: CVE Database V5
Vendor/Project: NLnet Labs
Product: Unbound

Description

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the compression tree lookup failure and eventually not increment the compression counter for those operations. Unbound 1.25.1 contains a patch with a fix that increments the compression counter regardless of the compression tree lookup. This is a complement fix to CVE-2024-8508.

CVSS v4.0

Score 6.9medium

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
Low
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/U:Amber

Affected software

GitHub Actionsmore threats →ai
nlnetlabs/unbound
pkg:github/nlnetlabs/unbound
Affected versions
<1.25.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/30/2026, 21:57:55 UTC

Technical Analysis

CVE-2026-44390 describes an inefficient algorithmic complexity vulnerability in NLnet Labs Unbound DNS resolver up to version 1.25.0. When Unbound handles replies containing very large RRsets that require name compression, specially crafted malicious responses with records that do not share a suffix above the root cause Unbound to enter an unbounded processing loop. This happens because the compression counter, introduced in version 1.21.1 to limit compression operations, is not incremented when the compression tree lookup fails due to lack of shared suffixes. As a result, Unbound can spend excessive CPU time compressing names before replying, leading to degraded performance and denial of service. The issue is fixed in version 1.25.1 by ensuring the compression counter increments regardless of compression tree lookup success. This fix complements a previous related fix (CVE-2024-8508). The vulnerability is rated medium severity with a CVSS 4.0 score of 6.9. Red Hat has issued an important security advisory providing patched packages for affected Red Hat Enterprise Linux 10 variants.

Potential Impact

The vulnerability allows an unauthenticated remote attacker to cause a denial of service by sending malicious DNS responses with very large RRsets that trigger excessive CPU consumption in Unbound during name compression. This can degrade resolver performance and potentially lock the CPU until the packet processing completes, impacting availability of DNS resolution services. There is no indication of privilege escalation, data disclosure, or integrity impact. The CVSS 4.0 base score of 6.9 reflects a medium severity denial of service impact with network attack vector and low attack complexity.

Mitigation Recommendations

A fix is available in Unbound version 1.25.1 that corrects the compression counter behavior to prevent unbounded CPU consumption. Users should upgrade to version 1.25.1 or later. Red Hat has released patched packages for Red Hat Enterprise Linux 10 and related variants; applying these updates will remediate the vulnerability. No other mitigations or workarounds are specified. Patch status is confirmed by the vendor advisory. Users should consult the Red Hat advisory at https://access.redhat.com/security/cve/CVE-2026-44390 and apply the recommended updates promptly.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
NLnet Labs
Date Reserved
2026-05-07T10:07:51.828Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-44390","vendor":"Red Hat"}]

Threat ID: 6a0d8700ba1db4736270eed7

Added to database: 05/20/2026, 10:03:44 UTC

Last enriched: 07/30/2026, 21:57:55 UTC

Last updated: 07/31/2026, 21:26:44 UTC

Views: 86

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses