CVE-2026-44608
Last modified
CVE-2026-44608 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a locking inconsistency vulnerability that when certain conditions are met (multi-threaded, RPZ XFR reload, RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers) it could result in heap use-after-free and eventual crash. An adversary can exploit the vulnerability if conditions are first met on a vulnerable Unbound, i.e., multi-threaded, an RPZ zone with 'rpz-nsip'/'rpz-nsdname' triggers and an ongoing XFR for that RPZ zone. Local RPZ files do not trigger the vulnerability. If the timing is right and an XFR happens at the same time another thread needs to read that RPZ zone, the reader may not hold the lock long enough and the thread applying the XFR may free objects that the reader is about to walk causing the use-after-free. Unbound 1.25.1 contains a patch with a fix to the locking code.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nlnetlabs | Unbound | >= 1.14.0, < 1.25.1 |
References
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44608.txtMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-44608?
How severe is CVE-2026-44608?
How do I fix CVE-2026-44608?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44600Tor before 0.4.9.7 mishandles accounting of the conflux out-…5.3
- CVE-2026-44601Tor before 0.4.9.7, when circuit queue memory pressure exist…7.5
- CVE-2026-44602Tor before 0.4.9.7 has a NULL pointer dereference when a CER…7.5
- CVE-2026-44603Tor before 0.4.9.7 has an out-of-bounds read by one byte via…9.1
- CVE-2026-44604A command injection vulnerability was discovered in the `rpm…7
- CVE-2026-44605A flaw was found in the RPM Package Manager (RPM). A local u…5.5
- CVE-2026-44609Local privilege escalation due to EXE hijacking vulnerabilit…7.3
- CVE-2026-4461Inappropriate implementation in V8 in Google Chrome prior to…8.8
- CVE-2026-44611Danelec MacGregor Voyage Data Recorder passwords are stored …5.9
- CVE-2026-44612Bytello Share (Windows Edition) installer executable provide…8.4
- CVE-2026-44613Cross-Site Request Forgery (CSRF) vulnerability in Apache Ze…6.1
- CVE-2026-44615Path traversal vulnerability in Apache Zeppelin. When FileSy…6.5
Are you affected by CVE-2026-44608?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
