CVE Explorer
CVE-2026-50046
In NLnet Labs Unbound 1.15.0 up to and including 1.25.1, the TLS server name used for DNS-over-TLS (DoT) forwarded queries is tied to a struct's ('serviced_query') lifetime but also referenced by another struct ('waiting_tcp'). When the owning struct is jostled out of the mesh while the DoT TCP stream is still handshaking it frees the storage behind the referenced string and if the TLS stream then errors out, it dereferences the freed pointer. The dereference is read-only and the practical impac
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Unbound","vendor":"NLnet Labs","versions":[{"lessThan":"1.25.2","status":"affected","version":"1.15.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:fbbd39aa681e71f1cf99dfe7f8e1afa3ff0fd9d8cd99fae8103b2104a5df8f34 · sha256:edf54390929bab9a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:fbbd39aa681e71f1cf99dfe7f8e1afa3ff0fd9d8cd99fae8103b2104a5df8f34 · sha256:edf54390929bab9a… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-416","description":"CWE-416: Use After Free","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:fbbd39aa681e71f1cf99dfe7f8e1afa3ff0fd9d8cd99fae8103b2104a5df8f34 · sha256:edf54390929bab9a… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50046.txt"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:fbbd39aa681e71f1cf99dfe7f8e1afa3ff0fd9d8cd99fae8103b2104a5df8f34 · sha256:edf54390929bab9a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.