OCTOBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-80225

MEDIUM · CVSS 5.3 EPSS 0.48%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-01

CyberRota Analysis

AI-Generated

NLnetLabs Unbound versions up to and including 1.26.0 are vulnerable to a degradation of service due to an unbounded number of consecutive reads in the TCP/DoT reading procedure. This allows a malicious actor to monopolize a worker's event loop by streaming distinct uncached names, potentially leading to service disruption. Organizations using affected versions should prioritize patching to mitigate the risk of denial-of-service attacks.

CVE
CVE-2026-80225
Severity
MEDIUM
CVSS
5.3
EPSS
0.48%

Original NVD Description

In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain.

Related CVEs

Other vulnerabilities affecting the same vendor(s)