What is CVE-2026-50045?
CVE-2026-50045 is a vulnerability in NLnet Labs Unbound versions 1.22.0 through 1.25.1 where a single client query for a deeply nested name under a DNSSEC-signed parent can exceed the configured 'max-global-quota' limit. This allows bypassing a security restriction on upstream packet rate per client query, potentially leading to increased resource consumption; users should update to the latest patched version.
Azərbaycanca: CVE-2026-50045 NLnet Labs Unbound 1.22.0-dan 1.25.1-ə qədər versiyalarda aşkar edilmiş zəiflikdir. DNSSEC ilə imzalanmış domen altında dərin yuvalanmış ad üçün edilən tək müştəri sorğusu, konfiqurasiya edilmiş 'max-global-quota' limitini keçərək daha çox upstream paket göndərilməsinə səbəb olur. Bu, təhlükəsizlik məhdudiyyətini yan keçərək resurs istehlakını artıra bilər; istifadəçilər Unbound-u ən son versiyaya yeniləməlidir.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
Which versions of NLnet Labs Unbound are affected by CVE-2026-50045?
This vulnerability affects NLnet Labs Unbound versions 1.22.0 through 1.25.1.
What security restriction related to the 'max-global-quota' parameter can be bypassed by CVE-2026-50045?
A single client query for a deeply nested name under a DNSSEC-signed parent can exceed the configured 'max-global-quota' limit, bypassing a security restriction on the upstream packet rate per client query.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.