Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
This issue is fixed starting with version 1.25.2
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 22 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Jul 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic. | |
| Title | 'max-global-quota' reset by DNSSEC validation restarts | |
| Weaknesses | CWE-406 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: NLnet Labs
Published:
Updated: 2026-07-22T18:57:09.417Z
Reserved: 2026-06-22T12:27:22.806Z
Link: CVE-2026-50045
Updated: 2026-07-22T18:57:04.674Z
No data.
No data.
OpenCVE Enrichment
No data.