What is CVE-2026-54478?
In NLnet Labs Unbound versions 1.18.0 to 1.25.1 with proxy-protocol-port and answer-cookie enabled, the SipHash server cookie is incorrectly calculated over the proxy's wire address instead of the PROXYv2 client address. This vulnerability can facilitate DNS amplification attacks. Affected systems should disable the answer-cookie option or update Unbound immediately.
Azərbaycanca: NLnet Labs Unbound-un 1.18.0–1.25.1 versiyalarında `proxy-protocol-port` aktiv olduqda SipHash server kukisi səhvən PROXY protokolunun elan etdiyi müştəri əvəzinə proksinin IP ünvanı üzərindən hesablanır. Bu zəiflik DNS amplifikasiya hücumlarına şərait yaradır. Təsirə məruz qalan sistemlərdə `answer-cookie` parametri deaktiv edilməli və ya proqram yenilənməlidir.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
What is the core configuration flaw that leads to the amplification attack?
In NLnet Labs Unbound versions 1.18.0 to 1.25.1 with proxy-protocol-port enabled, the SipHash server cookie is incorrectly calculated over the proxy's IP address instead of the client’s when answer-cookie is active.
What immediate step should be taken on affected systems to mitigate the attack risk?
Disable the answer-cookie option or update Unbound immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.