Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
This issue is fixed starting with version 1.26.1
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 16 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1050 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 16 Sep 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain. | |
| Title | Possible degradation of service from continuous queries on the same TCP/DoT connection | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: NLnet Labs
Published:
Updated: 2026-09-16T14:33:08.344Z
Reserved: 2026-09-07T14:06:21.952Z
Link: CVE-2026-80225
Updated: 2026-09-16T14:33:01.748Z
Status : Awaiting Analysis
Published: 2026-09-16T09:17:06.100
Modified: 2026-09-16T19:41:10.423
Link: CVE-2026-80225
OpenCVE Enrichment
Updated: 2026-09-16T14:15:09Z