{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-55717","assignerOrgId":"206fc3a0-e175-490b-9eaa-a5738056c9f6","state":"PUBLISHED","assignerShortName":"NLnet Labs","dateReserved":"2026-06-22T12:27:22.813Z","datePublished":"2026-07-22T13:09:40.927Z","dateUpdated":"2026-07-22T14:07:31.075Z"},"containers":{"cna":{"title":"'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash","datePublic":"2026-07-22T00:00:00.000Z","affected":[{"vendor":"NLnet Labs","product":"Unbound","versions":[{"version":"1.10.0","status":"affected","lessThan":"1.25.2","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"In NLnet Labs Unbound 1.10.0 up to and including 1.25.1, when 'serve-expired: yes' is set together with a 'response-ip: <net> redirect' /'response-ip-data: <net> CNAME <target>' rule (or the RPZ 'rpz-cname-override' equivalent), a remote client who controls any delegated domain can crash the daemon. The serve-expired-client-timeout callback runs a two-pass loop to chase the respip-generated CNAME alias; on the second pass it resets 'alias_rrset' but not 'partial_rep'. Later, this inconsistency leads to a NULL pointer dereference and an eventual crash. A malicious actor can exploit the vulnerability by controlling any zone that replies with an A/AAAA record that falls inside the configured response-ip/rpz subnet. By delaying the answer when the previous record has expired, the vulnerable path of 'serve-expired-client-timeout' is taken leading to denial of service via the server crash."}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"}}],"problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-476","description":"CWE-476: NULL Pointer Dereference","type":"CWE"}]}],"solutions":[{"lang":"en","value":"This issue is fixed starting with version 1.25.2"}],"timeline":[{"time":"2026-05-05T00:00:00.000Z","lang":"en","value":"Issue reported by Qifan Zhang"},{"time":"2026-05-27T00:00:00.000Z","lang":"en","value":"Issue reported by Xin Wang"},{"time":"2026-05-27T00:00:00.000Z","lang":"en","value":"NLnet Labs shares patch with Xin Wang"},{"time":"2026-05-27T00:00:00.000Z","lang":"en","value":"Xin Wang verifies patch"},{"time":"2026-05-29T00:00:00.000Z","lang":"en","value":"NLnet Labs shares patch with Qifan Zhang"},{"time":"2026-06-03T00:00:00.000Z","lang":"en","value":"Qifan Zhang verifies patch"},{"time":"2026-07-22T00:00:00.000Z","lang":"en","value":"Fixes released with version 1.25.2"}],"credits":[{"lang":"en","value":"Qifan Zhang (Palo Alto Networks)","type":"finder"},{"lang":"en","value":"Xin Wang (Northwestern Polytechnical University)","type":"finder"},{"lang":"en","value":"Jiapeng Li (Northwestern Polytechnical University)","type":"finder"},{"lang":"en","value":"Jiajia Liu (Northwestern Polytechnical University)","type":"finder"}],"references":[{"url":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55717.txt","tags":["vendor-advisory"]}],"providerMetadata":{"orgId":"206fc3a0-e175-490b-9eaa-a5738056c9f6","shortName":"NLnet Labs","dateUpdated":"2026-07-22T13:09:40.927Z"},"x_generator":{"engine":"cvelib 1.8.0"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-22T14:07:12.831423Z","id":"CVE-2026-55717","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-22T14:07:31.075Z"}}]}}