What is CVE-2026-50046?
A use-after-free vulnerability has been discovered in NLnet Labs Unbound DNS resolver (versions 1.15.0 through 1.25.1) related to TLS server name handling in DNS-over-TLS (DoT) forwarded queries. The issue occurs when the 'serviced_query' struct is jostled out of the mesh while its TLS server name is still referenced by a 'waiting_tcp' struct. Users should immediately upgrade Unbound to the latest patched version.
Azərbaycanca: NLnet Labs Unbound DNS həlledicisində (1.15.0-dən 1.25.1-ə qədər) DNS-over-TLS (DoT) yönləndirilmiş sorğularda TLS server adının 'use-after-free' boşluğu aşkarlanıb. Bu zəiflik, 'serviced_query' strukturu mesh-dən çıxarıldıqda digər 'waiting_tcp' strukturu tərəfindən istinad edilən yaddaşın istifadəsinə səbəb olur. İstifadəçilər dərhal Unbound-u ən son versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
What software is affected by CVE-2026-50046?
This vulnerability affects NLnet Labs Unbound DNS resolver versions 1.15.0 through 1.25.1.
What should users do to prevent exploitation of CVE-2026-50046?
Users should immediately upgrade Unbound to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.