{"id":"CVE-2019-16866","title":"Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query","summary":"Unbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-755","CWE-908","CWE-822"],"vendor":"nlnetlabs","product":"unbound","affected":["unbound < 1.9.4","ubuntu_linux = 19.04"],"patched":["unbound 1.9.4"],"published":"2019-10-03","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:16.327","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-16866","references":[{"url":"https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E65NCWZZB2D75ZIYWPXKMVGSGNYW4JMC/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MLRHE7TQFAOV4MB2ELTOGESZYUL65NUJ/","label":"cve@mitre.org"},{"url":"https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt","label":"cve@mitre.org"},{"url":"https://seclists.org/bugtraq/2019/Oct/23","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4149-1/","label":"cve@mitre.org"},{"url":"https://www.debian.org/security/2019/dsa-4544","label":"cve@mitre.org"},{"url":"https://github.com/NLnetLabs/unbound/blob/release-1.9.4/doc/Changelog","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E65NCWZZB2D75ZIYWPXKMVGSGNYW4JMC/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MLRHE7TQFAOV4MB2ELTOGESZYUL65NUJ/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://nlnetlabs.nl/downloads/unbound/CVE-2019-16866.txt","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://seclists.org/bugtraq/2019/Oct/23","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4149-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2019/dsa-4544","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-16866.json"},{"url":"https://access.redhat.com/security/cve/CVE-2019-16866"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1767955"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-16866"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16866"}],"tags":["nvd","csaf","vex","red-hat","score-dispute"],"epss":0.03506,"epssPercentile":0.88863,"ingestedAt":"2026-10-08T22:11:53.702Z","scores":{"nvd":7.5,"vendor":5.3},"slug":"CVE-2019-16866","body":"## Overview\n\nUnbound before 1.9.4 accesses uninitialized memory, which allows remote attackers to trigger a crash via a crafted NOTIFY query. The source IP address of the query must match an access-control rule.\n\n## Affected\n\n- `unbound < 1.9.4`\n- `ubuntu_linux = 19.04`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `unbound 1.9.4`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Low · affected: Red Hat Enterprise Linux 8 · no fix planned: Red Hat Enterprise Linux 8 · updated 2026-10-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2019/cve-2019-16866.json)","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.7,"exploitation":0,"ransomware":0},"changes":[]}