In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-16 09:17
Updated : 2026-09-16 09:17
NVD link : CVE-2026-80225
Mitre link : CVE-2026-80225
CVE.ORG link : CVE-2026-80225
JSON object : View
Products Affected
No product.
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
