Unbound is a widely deployed recursive DNS resolver used in both enterprise and service-provider environments, and its vulnerability footprint remains narrow and focused on the single resolver product. The limited disclosure history centers on DNS protocol parsing and resolver logic, reflecting the core attack surface of a DNS software component. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unbound over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4869HIGH validator/val_nsec3.c in Unbound before 1.4.13p2 does not properly perform proof processing for NSEC3-signed zones, which allows remote DNS servers to cause a denial of service (da | Dec 20, 2011 | 7.8 | 24 | NO | NO |
CVE-2012-1192MEDIUM The resolver in Unbound before 1.4.11 overwrites cached server names and TTL values in NS records during the processing of a response to an A record query, which allows remote atta | Feb 17, 2012 | 6.4 | 21 | NO | NO |
CVE-2011-4528MEDIUM Unbound before 1.4.13p2 attempts to free unallocated memory during processing of duplicate CNAME records in a signed zone, which allows remote DNS servers to cause a denial of serv | Dec 20, 2011 | 5.0 | 21 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unbound.
Media articles that mention a CVE ID that affects a product developed by Unbound — matched by CVE ID, not by vendor name.