CVE-2019-16866: High severity nlnetlabs Unbound vulnerability
Last updated 25 August 2025
Other sources
Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16866?
CVE-2019-16866 is a vulnerability in Unbound before version 1.9.4 that allows remote attackers to trigger a crash via a crafted NOTIFY query by accessing uninitialized memory.
How does CVE-2019-16866 affect Unbound?
CVE-2019-16866 affects Unbound versions before 1.9.4.
What is the severity of CVE-2019-16866?
CVE-2019-16866 has a severity rating of 7.5 (High).
How can I fix CVE-2019-16866?
To fix CVE-2019-16866, update Unbound to version 1.9.4 or higher.
Where can I find more information about CVE-2019-16866?
More information about CVE-2019-16866 can be found at the following references: [CVE-2019-16866](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16866), [NLnetlabs](https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt), [GitHub](https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog).