NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution… (CVE-2026-42534)
NLnet Labs Unbound up to and including version 1.25.0 contains a vulnerability in its jostle logic that can degrade DNS resolution performance. The flaw allows retransmitted duplicate queries to reset the aging timer of slow queries, preventing their replacement and potentially causing denial of resolution service under coordinated attack. Cache and local data responses are not affected. Unbound 1.25.1 includes a patch that fixes this by attaching a fixed start time to queries, enabling proper aging and replacement logic.
AI Analysis
Technical Summary
The vulnerability in NLnet Labs Unbound (CVE-2026-42534) affects the jostle logic responsible for managing slow DNS queries when the 'num-queries-per-thread' limit is reached. Duplicate retransmitted queries renew the age timestamp of slow queries, preventing the jostle logic from identifying and replacing aged queries with new ones. An attacker controlling a slow or malicious authoritative DNS server can exploit this to degrade resolution performance or cause denial of resolution service. The vulnerability does not impact cache or local data responses. The issue is fixed in Unbound version 1.25.1 by introducing an immutable start time for each query, ensuring the jostle logic functions correctly.
Potential Impact
An adversary able to query a vulnerable Unbound resolver and control a slow or malicious authoritative DNS server can exploit this vulnerability to degrade DNS resolution performance. This can lead to denial of resolution service when the resolver's query limit is reached and the jostle logic fails to replace slow queries due to skewed aging caused by duplicate retransmissions. Cache and local data responses remain unaffected, limiting the impact to recursive resolution performance degradation.
Mitigation Recommendations
A fix is available in Unbound version 1.25.1, which addresses the vulnerability by attaching an initial, non-updatable start time to incoming queries to enable proper jostle logic operation. Users should upgrade to version 1.25.1 or later to remediate this issue. No other mitigations are specified by the vendor advisory.
NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution… (CVE-2026-42534)
Description
NLnet Labs Unbound up to and including version 1.25.0 contains a vulnerability in its jostle logic that can degrade DNS resolution performance. The flaw allows retransmitted duplicate queries to reset the aging timer of slow queries, preventing their replacement and potentially causing denial of resolution service under coordinated attack. Cache and local data responses are not affected. Unbound 1.25.1 includes a patch that fixes this by attaching a fixed start time to queries, enabling proper aging and replacement logic.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in NLnet Labs Unbound (CVE-2026-42534) affects the jostle logic responsible for managing slow DNS queries when the 'num-queries-per-thread' limit is reached. Duplicate retransmitted queries renew the age timestamp of slow queries, preventing the jostle logic from identifying and replacing aged queries with new ones. An attacker controlling a slow or malicious authoritative DNS server can exploit this to degrade resolution performance or cause denial of resolution service. The vulnerability does not impact cache or local data responses. The issue is fixed in Unbound version 1.25.1 by introducing an immutable start time for each query, ensuring the jostle logic functions correctly.
Potential Impact
An adversary able to query a vulnerable Unbound resolver and control a slow or malicious authoritative DNS server can exploit this vulnerability to degrade DNS resolution performance. This can lead to denial of resolution service when the resolver's query limit is reached and the jostle logic fails to replace slow queries due to skewed aging caused by duplicate retransmissions. Cache and local data responses remain unaffected, limiting the impact to recursive resolution performance degradation.
Mitigation Recommendations
A fix is available in Unbound version 1.25.1, which addresses the vulnerability by attaching an initial, non-updatable start time to incoming queries to enable proper jostle logic operation. Users should upgrade to version 1.25.1 or later to remediate this issue. No other mitigations are specified by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-xfcv-gp55-3wpf
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-42534"]
- Ecosystems
- []
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6a6ae5599c2644c7f89a9601
Added to database: 07/30/2026, 05:47:05 UTC
Last enriched: 07/30/2026, 07:27:34 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.