CVE-2026-50046: CWE-416: Use After Free in NLnet Labs Unbound
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.
AI Analysis
Technical Summary
CVE-2026-50046 is a use-after-free vulnerability (CWE-416) in NLnet Labs Unbound DNS resolver versions 1.15.0 through 1.25.1. The issue arises because the TLS server name string used for DNS-over-TLS forwarded queries is tied to the lifetime of a 'serviced_query' struct but also referenced by a 'waiting_tcp' struct. If the 'serviced_query' struct is removed while the DoT TCP stream is still handshaking, the memory behind the TLS server name string is freed. If the TLS stream then encounters an error, it dereferences this freed pointer in a read-only manner, causing the Unbound daemon to crash. Exploitation requires a vulnerable configuration with a stub/forward zone using DoT and a configured '#authname' suffix, plus a transient failure in connectivity at a precise time to trigger the error path. The vulnerability results in denial of service but does not impact confidentiality or integrity.
Potential Impact
Successful exploitation causes a denial of service by crashing the Unbound daemon. There is no impact on confidentiality or integrity. The vulnerability requires specific configuration and timing conditions, limiting the ease of exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider avoiding configurations that combine stub/forward zones with DoT and '#authname' suffixes, or monitor for updates from NLnet Labs. No official fix or workaround is currently documented.
CVE-2026-50046: CWE-416: Use After Free in NLnet Labs Unbound
Description
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.
CVSS v3.1
Score 5.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-50046 is a use-after-free vulnerability (CWE-416) in NLnet Labs Unbound DNS resolver versions 1.15.0 through 1.25.1. The issue arises because the TLS server name string used for DNS-over-TLS forwarded queries is tied to the lifetime of a 'serviced_query' struct but also referenced by a 'waiting_tcp' struct. If the 'serviced_query' struct is removed while the DoT TCP stream is still handshaking, the memory behind the TLS server name string is freed. If the TLS stream then encounters an error, it dereferences this freed pointer in a read-only manner, causing the Unbound daemon to crash. Exploitation requires a vulnerable configuration with a stub/forward zone using DoT and a configured '#authname' suffix, plus a transient failure in connectivity at a precise time to trigger the error path. The vulnerability results in denial of service but does not impact confidentiality or integrity.
Potential Impact
Successful exploitation causes a denial of service by crashing the Unbound daemon. There is no impact on confidentiality or integrity. The vulnerability requires specific configuration and timing conditions, limiting the ease of exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider avoiding configurations that combine stub/forward zones with DoT and '#authname' suffixes, or monitor for updates from NLnet Labs. No official fix or workaround is currently documented.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- NLnet Labs
- Date Reserved
- 2026-06-22T12:27:22.824Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a60c4229c2644c7f80e923b
Added to database: 07/22/2026, 13:22:42 UTC
Last enriched: 07/22/2026, 13:40:22 UTC
Last updated: 07/22/2026, 21:09:13 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.