Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-42534

26
FAUCET Score

NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the same query could renew the age of slow running queries and not allow the jostle logic to see them as aged and potential targets for replacement with new queries. An adversary who can query a vulnerable Unbound and who can control a domain name server that replies slowly and/or maliciously to Unbound's queries can exploit the vulnerability and degrade the resolution performance of Unbound. When Unbound's 'num-queries-per-thread' reaches its limit, the jostle logic kicks in. When a new query comes in, half of the available queries that are also slow to resolve are candidates for replacement. The vulnerability then happens because duplicate queries that need resolution would skew the aging result by using the timestamp of the latest duplicate query instead of the original one that started the resolution effort. Cache and local data response performance remains unaffected. Coordinated attacks could raise this to a denial of resolution service. Unbound 1.25.1 contains a patch with a fix to attach an initial, non-updatable start time for incoming queries that allow the jostle logic to work as intended.

First published: May 20, 2026Last modified: May 20, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 1.25.1CPE matchmatch criteria
cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*
>= 0, < 1.25.1CPE match
cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.9MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
NONE
VS Integrity
NONE
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.52%
Probability of exploitation in next 30 days
EPSS Percentile
41.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0052 is in the 26th percentile among its peer group of 23,705 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: 20736-17084Fixed in: 1.25.1-1
microsoftpatch availablevia msrc
Product: azl3 unbound 1.19.1-5 on Azure Linux 3.0Fixed in: 1.25.1-1
ubuntupatch availablevia ubuntu_usn
Product: unbound (jammy)Fixed in: 1.13.1-1ubuntu5.15
ubuntupatch availablevia ubuntu_usn
Product: unbound (noble)Fixed in: 1.19.2-1ubuntu3.8
ubuntupatch availablevia ubuntu_usn
Product: unbound (questing)Fixed in: 1.22.0-2ubuntu2.3
ubuntupatch availablevia ubuntu_usn
Product: unbound (resolute)Fixed in: 1.24.2-1ubuntu2.1

Vendor Advisories (2)

ubuntuUSN-8282-1

Unbound vulnerabilities

May 20, 2026
microsoft2026-May/CVE-2026-42534Low

Jostle logic bypass degrades resolution performance

May 12, 2026

References

access.redhat.com / errata/RHSA-2026:24013
access.redhat.com / security/cve/CVE-2026-42534
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-42534.json
nlnetlabs.nl / downloads/unbound/CVE-2026-42534.txt
MitigationVendor Advisory