CVE-2026-44390Patch(nlnetlabs / unbound)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nlnetlabs unbound systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability when handling replies with very large RRsets that Unbound needs to perform name compression for. Malicious upstream responses with very large RRsets with records that don't share a suffix above the root can cause Unbound to spend a considerable time applying name compression to downstream replies. This can lead to degraded performance and eventually denial of service in well orchestrated attacks. An adversary can exploit the vulnerability by querying Unbound for the specially crafted contents of a malicious zone with very large RRsets. Before Unbound replies to the query it will try to apply name compression which was an unbounded operation that could lock the CPU until the whole packet was complete. A compression limit was introduced in 1.21.1 for this but it didn't account for the case where records would not share any suffix above the root. That causes Unbound to go in a different code path because of the compression tree lookup failure and eventually not increment the compression counter for those operations. Unbound 1.25.1 contains a patch with a fix that increments the compression counter regardless of the compression tree lookup. This is a complement fix to CVE-2024-8508.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-407CWE-1050

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unbound

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Peaked 1d ago at 2 mentions (2026-05-20); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
unbound

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-20: 2Mentions · 2026-05-27: 1Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-05-27: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-27: 105-2005-27
Signal classification1 categories
Patch
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-202
Patch2
2026-05-271
Patch1
Full discourse3 posts
  • Yasuhiro Morishita@OrangeMorishita
    Patch

    ・Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42959, Crash during DNSSEC validation of malicious content. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks to Andrew Griffiths from ‘http://calif.io’ for the report. ・Fix CVE-2026-40622, “Ghost domain name” variant. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-41292, Parsing a long list of incoming EDNS options degrades performance. Thanks to GitHub user ‘N0zoM1z0’, also Qifan Zhang from Palo Alto Networks, for the report. ・Fix CVE-2026-42534, Jostle logic bypass degrades resolution performance. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42923, Degradation of service with unbounded NSEC3 hash calculations. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42960, Possible cache poisoning attack while following delegation. Thanks to TaoFei Guo from Peking University, Yang Luo and JianJun Chen, Tsinghua University, for the report. ・Fix CVE-2026-44390, Unbounded name compression in certain cases causes degradation of service. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

    Post summary

    The text lists multiple CVE patches with brief technical descriptions, highlighting that fixes are available for each vulnerability.

    11010442
    4.5K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Patch

    "This release consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608."

    Post summary

    The release announces the availability of patches for a list of CVEs, highlighting remediation steps.

    10000228
    4.5K followersView on X
  • WindowsForum@windowsforum
    Patch

    🚨 CVE-2026-44390 is the classic “can’t hack your PC, but can hog its brain” DNS DoS. Windows DNS resolvers getting throttled? That’s downtime, not data theft. Patch fast. https://windowsforum.com/threads/cve-2026-44390-unbound-dos-patch-unbounded-name-compression-bottleneck-windows.420038/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #PatchManagement #DnsDenialOfService #UnboundDns #Cve202644390 https://t.co/fLAvQToFcG

    Post summary

    This post highlights CVE‑2026‑44390, a DNS denial‑of‑service flaw affecting Windows DNS resolvers, and urges users to apply the available patch.

    0000056
    1.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnlnetlabsunbound---

Explore more