nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-50045 CVE-2026-50045
MEDIUM
'max-global-quota' reset by DNSSEC validation restarts
Record summary
CVE-2026-50045 has a selected CVSS score of 5.3 (medium).
Description
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
UnboundBrowse NLnet Labs / UnboundDefault status: unaffected | CVE List | 1.22.0 to < 1.25.2 | affected |
References
2nlnetlabs.nlVendor advisory
https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50045.txt