SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-55717

MEDIUM · CVSS 5.9 EPSS 0.24% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Unbound versions 1.10.0 through 1.25.1 are vulnerable when the 'serve-expired: yes' option is enabled alongside specific response IP rules, allowing a remote attacker controlling a delegated domain to exploit a NULL pointer dereference. This can lead to a denial of service by crashing the daemon, particularly if the attacker can manipulate DNS responses within the configured response IP subnet. Organizations using affected versions of Unbound should prioritize patching to mitigate potential service disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-55717
Severity
MEDIUM
CVSS
5.9
EPSS
0.24%

Original NVD Description

In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash.

Related CVEs

Other vulnerabilities affecting the same vendor(s)