What is CVE-2026-44621?
In NLnet Labs Unbound up to version 1.25.1, applications using libunbound with the 'unwanted-reply-threshold' option enabled may crash unexpectedly when the threshold is reached, due to a missing 'libworker_alloc_cleanup' function. This affects any software relying on the vulnerable libunbound library. Users should update to a patched version or adjust the configuration to mitigate the issue.
Azərbaycanca: NLnet Labs Unbound-un 1.25.1-ə qədər versiyalarında tətbiqlərin 'unwanted-reply-threshold' parametri aktiv olduqda, hədd aşıldıqda 'libworker_alloc_cleanup' funksiyasının olmaması səbəbilə qəfil sonlandırma baş verir. Bu zəiflik libunbound istifadə edən tətbiqlərə təsir edir. İstifadəçilərə dərhal yamaqlı versiyaya yeniləmə və ya konfiqurasiyanı nəzərdən keçirmə tövsiyə olunur.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
Which versions of NLnet Labs Unbound are affected by CVE-2026-44621?
NLnet Labs Unbound versions up to 1.25.1 are affected by this vulnerability.
What configuration issue triggers the vulnerability in affected applications?
When the 'unwanted-reply-threshold' option is enabled, the application crashes unexpectedly upon reaching the threshold due to a missing 'libworker_alloc_cleanup' function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.