CVE-2026-50045: 'max-global-quota' reset by DNSSEC validation restarts
'max-global-quota' reset by DNSSEC validation restarts
Other sources
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.25.2-1 - Upgrade
Upgrade
NLnet Labs Unboundto a version that resolves this vulnerability.Fixed in 1.25.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50045?
CVE-2026-50045 has a medium severity rating of 5.3.
How do I fix CVE-2026-50045?
To mitigate CVE-2026-50045, consider updating Unbound to a version later than 1.25.1.
What causes CVE-2026-50045 to occur?
CVE-2026-50045 occurs when a deeply nested query under a DNSSEC-signed parent causes Unbound to exceed the configured 'max-global-quota'.
What impact does CVE-2026-50045 have on my system?
CVE-2026-50045 may lead to excessive upstream packet sending, potentially affecting performance.
Which versions of Unbound are affected by CVE-2026-50045?
CVE-2026-50045 affects NLnet Labs Unbound versions 1.22.0 through 1.25.1.