CVE-2026-50045 PUBLISHED

'max-global-quota' reset by DNSSEC validation restarts

Assigner: NLnet Labs
Reserved: 22.06.2026 Published: 22.07.2026 Updated: 22.07.2026

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS Score: 5.3

Product Status

Vendor NLnet Labs
Product Unbound
Versions Default: unaffected
  • affected from 1.22.0 to 1.25.2 (excl.)

Solutions

This issue is fixed starting with version 1.25.2

Credits

  • Kunjie Shang (University of Science and Technology of China) finder

References

Problem Types

  • CWE-406: Insufficient Control of Network Message Volume (Network Amplification) CWE