Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-32792

27
FAUCET Score

NLnet Labs Unbound 1.6.2 up to and including version 1.25.0 has a denial of service vulnerability when compiled with DNSCrypt support ('--enable-dnscrypt'). A bad DNSCrypt query could underflow Unbound's DNSCrypt packet reading procedure that may lead to heap overflow. A malicious actor can exploit the vulnerability with a single bad DNSCrypt query that its decrypted plaintext consists entirely of '0x00' bytes and does not contain the expected '0x80' marker. Unbound would then start reading more bytes than necessary until it finds a non-'0x00' byte. Based on the underlying memory allocator and the memory layout, it could lead to heap overflow while reading followed by a crash. Likelihood of a crash is low, since it relies heavily on the underlying memory allocator and the memory layout. If the heap overflow does not happen, Unbound's later packet checks will deny the packet. Unbound 1.25.1 contains a patch with a fix to bound reading in the given buffer space.

First published: May 20, 2026Last modified: May 20, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.6.2, < 1.25.1CPE matchmatch criteria
cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

4.6MEDIUM

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Green

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
PRESENT
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 15th percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

microsoftpatch availablevia msrc
Product: azl3 unbound 1.19.1-5 on Azure Linux 3.0Fixed in: 1.25.1-1
microsoftpatch availablevia msrc
Product: 20736-17084Fixed in: 1.25.1-1
ubuntupatch availablevia ubuntu_usn
Product: unbound (questing)Fixed in: 1.22.0-2ubuntu2.3
ubuntupatch availablevia ubuntu_usn
Product: unbound (resolute)Fixed in: 1.24.2-1ubuntu2.1
ubuntupatch availablevia ubuntu_usn
Product: unbound (jammy)Fixed in: 1.13.1-1ubuntu5.15
ubuntupatch availablevia ubuntu_usn
Product: unbound (noble)Fixed in: 1.19.2-1ubuntu3.8
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: unbound
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: unbound
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: unbound
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: unbound
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: unbound
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatno patchvia redhat_api
Product: Red Hat Hardened ImagesFixed in: unbound

Vendor Advisories (3)

redhatCVE-2026-32792Moderate

unbound: Packet of death with DNSCrypt

May 26, 2026
ubuntuUSN-8282-1

Unbound vulnerabilities

May 20, 2026
microsoft2026-May/CVE-2026-32792Moderate

Packet of death with DNSCrypt

May 12, 2026

References

nlnetlabs.nl / downloads/unbound/CVE-2026-32792.txt
MitigationVendor Advisory