{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-44621","assignerOrgId":"206fc3a0-e175-490b-9eaa-a5738056c9f6","state":"PUBLISHED","assignerShortName":"NLnet Labs","dateReserved":"2026-06-22T10:11:10.524Z","datePublished":"2026-07-22T13:06:28.947Z","dateUpdated":"2026-07-22T14:21:22.388Z"},"containers":{"cna":{"title":"Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated","datePublic":"2026-07-22T00:00:00.000Z","affected":[{"vendor":"NLnet Labs","product":"Unbound","versions":[{"version":"0","status":"affected","lessThan":"1.25.2","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"With NLnet Labs Unbound up to and including version 1.25.1, applications using libunbound and configured with 'unwanted-reply-threshold', could eventually be abruptly terminated if the threshold is reached and libunbound needs to call 'libworker_alloc_cleanup' since the function is absent from the function call allow list. When an application using libunbound sets 'unwanted-reply-threshold' to any non-zero value and the iterator queries an authoritative that replies with enough wrong-transaction-ID UDP datagrams to cross the threshold, the 'libworker_alloc_cleanup' will eventually be called. Since the function is absent from the function call allow list, this leads to a fatal exit of libunbound and eventual termination of the embedding application.Unbound itself is not affected since its relevant function 'worker_alloc_cleanup' is registed in the allow list and proceeds to perform the documented cache flush."}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"Libunbound applications"}],"cvssV3_1":{"version":"3.1","baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}}],"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-754","description":"CWE-754: Improper Check for Unusual or Exceptional Conditions","type":"CWE"}]}],"solutions":[{"lang":"en","value":"This issue is fixed starting with version 1.25.2"}],"timeline":[{"time":"2026-05-18T00:00:00.000Z","lang":"en","value":"Issue reported by Qifan Zhang"},{"time":"2026-06-10T00:00:00.000Z","lang":"en","value":"NLnet Labs shares patch"},{"time":"2026-06-13T00:00:00.000Z","lang":"en","value":"Qifan Zhang verifies patch"},{"time":"2026-07-22T00:00:00.000Z","lang":"en","value":"Fixes released with version 1.25.2"}],"credits":[{"lang":"en","value":"Qifan Zhang (Palo Alto Networks)","type":"finder"}],"references":[{"url":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-44621.txt","tags":["vendor-advisory"]}],"providerMetadata":{"orgId":"206fc3a0-e175-490b-9eaa-a5738056c9f6","shortName":"NLnet Labs","dateUpdated":"2026-07-22T13:06:28.947Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-22T14:21:13.870660Z","id":"CVE-2026-44621","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-22T14:21:22.388Z"}}]}}