CVE-2024-1488High· 8.0▾ TwilightA vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
0.3% → 0.3%
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuration of unbound.service. This flaw allows an unprivileged attacker to manipulate a running instance, potentially altering forwarders, allowing them to track all queries forwarded by the local resolver, and, in some cases, disrupting resolving altogether.
unbound < 1.19.1-2.fc40codeready_linux_builder = 9.0codeready_linux_builder_eus = 9.2codeready_linux_builder_eus = 9.4codeready_linux_builder_eus_for_power_little_endian = 9.0_ppc64lecodeready_linux_builder_eus_for_power_little_endian = 9.2_ppc64lecodeready_linux_builder_for_arm64 = 9.0_aarch64codeready_linux_builder_for_arm64 = 9.2_aarch64codeready_linux_builder_for_arm64_eus = 9.4_aarch64codeready_linux_builder_for_ibm_z_systems = 9.0_s390xcodeready_linux_builder_for_ibm_z_systems = 9.2_s390xcodeready_linux_builder_for_ibm_z_systems_eus = 9.4_s390xenterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux_eus = 8.6enterprise_linux_eus = 8.8enterprise_linux_eus = 9.2enterprise_linux_eus = 9.4enterprise_linux_for_arm_64 = 8.0_aarch64enterprise_linux_for_arm_64 = 9.0_aarch64enterprise_linux_for_arm_64 = 9.2_aarch64enterprise_linux_for_arm_64_eus = 8.6_aarch64enterprise_linux_for_arm_64_eus = 8.8_aarch64enterprise_linux_for_arm_64_eus = 9.4_aarch64enterprise_linux_for_ibm_z_systems = 8.0_s390xenterprise_linux_for_ibm_z_systems = 9.0_s390xenterprise_linux_for_ibm_z_systems = 9.2_s390xenterprise_linux_for_ibm_z_systems_eus = 8.6_s390xenterprise_linux_for_ibm_z_systems_eus = 8.8_s390xenterprise_linux_for_ibm_z_systems_eus = 9.4_s390xenterprise_linux_for_power_little_endian = 8.0_ppc64leenterprise_linux_for_power_little_endian = 9.0_ppc64leenterprise_linux_for_power_little_endian = 9.2_ppc64leenterprise_linux_for_power_little_endian_eus = 8.6_ppc64leenterprise_linux_for_power_little_endian_eus = 8.8_ppc64leenterprise_linux_for_power_little_endian_eus = 9.4_ppc64leenterprise_linux_server_aus = 8.2enterprise_linux_server_aus = 8.4enterprise_linux_server_aus = 8.6enterprise_linux_server_aus = 9.2enterprise_linux_server_aus = 9.4enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.2_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.4_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.6_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 8.8_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.2_ppc64leenterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions = 9.4_ppc64leenterprise_linux_server_tus = 8.2enterprise_linux_server_tus = 8.4enterprise_linux_server_tus = 8.6enterprise_linux_server_tus = 8.8Upgrade past the affected range:
unbound 1.19.1-2.fc40Connected by shared product, vendor, weakness, or advisory.
CVE-2026-32665High· 7.5Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
CVE-2026-55991Medium· 5.9Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
CVE-2026-77860Low· 3.7In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulnerability on the 'serve-expired' code path can cause a double decrement on the 'wait-limit' counter per client IP essentially bypassing one of the counter measures that was in…
CVE-2026-77955Medium· 4.4In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents ar…
CVE-2026-80225Medium· 5.3In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads
CVE-2026-78227Medium· 6.5NLnet Labs Unbound 1.22.0 up to and including 1.26.1, has a use-after-free vulnerability when compiled for DNS-over-QUIC support with '--with-libngtcp2'