📦

unbound

Vendor: nlnetlabs

Actively Exploited 0 CISA KEV List
PoC / Exploits 2 Code Available
Total RCEs 4 Remote Access
Total CVEs 325 Total Indexed
Avg. EPSS 3.12% Exploit Prob.
Latest CVE CVE-2026-56444 Jul 22

Security Vulnerability Index

Page 7 / 33
5.0 CVSS

Unbound before 1.4.4 does not send responses for signed zones after mishandling an unspecified query, which allows remote attackers to cause a denial of service (DNSSEC outage) via a crafted query.

EPSS: 2.70%
4.3 CVSS

daemon/worker.c in Unbound 1.x before 1.4.10, when debugging functionality and the interface-automatic option are enabled, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted DNS request that triggers improper error handling.

EPSS: 7.08%
5.0 CVSS

Unbound before 1.4.3 does not properly align structures on 64-bit platforms, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.

EPSS: 2.62%
7.5 CVSS

Unbound before 1.3.4 does not properly verify signatures for NSEC3 records, which allows remote attackers to cause secure delegations to be downgraded via DNS spoofing or other DNS-related attacks in conjunction with crafted delegation responses.

EPSS: 2.98%