CVE-2026-50046: Possible heap use-after-free in an error path when a DoT forwarded query is jostled out

Published Jul 22, 2026
·
Updated

In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('servicedquery') lifetime but also referenced by another struct ('waitingtcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impact is a daemon crash resulting in denial of service. A malicious actor that knows a DoT forwarding/stub Unbound's configuration could exploit the vulnerability by quering records in the appropriate zone while keeping Unbound uder pressure so that the jostle logic kicks in. If answers for the vulnerable zone are slow, the likelihood of jostling such queries is higher, although the timing of the jostle needs to be precise. Requirements for a vulnerable Unbound is the existence of a stub/forward zone configured for DoT together with a configured '#authname' suffix on the server identification. The connectivity to the server needs to exhibit a transient failure at the correct time in order to kick off the vulnerable error path.

Other sources

Possible heap use-after-free in an error path when a DoT forwarded query is jostled out

Microsoft

Affected Software

3 affected componentsFixes available
Nlnet Labs Unbound>=1.15.0<=1.25.1
Microsoft azl3 unbound 1.25.1-1<1.25.2-1
1.25.2-1
nlnetlabs Unbound>=1.15.0<1.25.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.25.2-1
  2. Upgrade

    Upgrade NLnet Labs Unbound to a version that resolves this vulnerability.

    Fixed in 1.25.2
  3. Compensating control

    If running an affected NLnet Labs Unbound version (1.15.0 through 1.25.1), reduce the ability for a malicious actor to trigger DoT forwarded query jostling by restricting/ACL’ing access so only trusted resolvers/clients can query the DoT stub/forwarded zones configured for DoT (and with a configured #authname server identification suffix).

  4. Operational

    After upgrading Unbound to 1.25.2 or later, restart the Unbound daemon to ensure the process using the previous heap state is fully replaced.

Event History

Jul 22, 2026
CVE Published
via MITRE·01:08 PM
Data Sourced
via MITRE·01:08 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Jul 23, 2026
Data Sourced
via Microsoft·08:04 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:04 AM
Affected Software
Updated
via Microsoft·08:04 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-50046?

CVE-2026-50046 has a medium severity score of 5.9.

2

How does CVE-2026-50046 affect Nlnet Labs Unbound?

CVE-2026-50046 can cause a use-after-free vulnerability in the handling of DNS-over-TLS queries.

3

What versions of Unbound are impacted by CVE-2026-50046?

CVE-2026-50046 affects Nlnet Labs Unbound versions from 1.15.0 up to and including 1.25.1.

4

How do I mitigate CVE-2026-50046?

To mitigate CVE-2026-50046, update Nlnet Labs Unbound to the latest patched version.

5

What is the nature of the vulnerability identified in CVE-2026-50046?

CVE-2026-50046 is a possible heap use-after-free vulnerability occurring in an error path related to DNS-over-TLS.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203