What is CVE-2026-55717?
A vulnerability in NLnet Labs Unbound DNS resolver allows remote denial of service. When 'serve-expired: yes' is configured with specific 'response-ip' redirect rules or RPZ 'rpz-cname-override', an attacker controlling a delegated domain can crash the daemon. Affected versions should be updated immediately.
Azərbaycanca: NLnet Labs Unbound DNS həlli üçün zəiflikdir. 'serve-expired: yes' aktiv edildikdə, xüsusi 'response-ip' redirect qaydaları ilə birgə işlədikdə, uzaqdan hücumçu idarə etdiyi domen vasitəsilə daemon-u çökdürə bilər. Təsirə məruz qalan versiyalar üçün istehsalçı tərəfindən yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
Under what conditions can CVE-2026-55717 in NLnet Labs Unbound be exploited?
This vulnerability can be exploited only when 'serve-expired: yes' is enabled in the Unbound configuration alongside specific 'response-ip' redirect rules.
What outcome can a remote attacker achieve by exploiting CVE-2026-55717?
A remote attacker can crash the Unbound daemon via a controlled domain, causing a denial of service (DoS) condition.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.