CVE Explorer
CVE-2026-55990
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when the 'dnscrypt:' clause lists more 'dnscrypt-provider-cert:' files than there are matching 'dnscrypt-secret-key:' files, Unbound fills only the matched prefix and leaves the tail slots at the '0xdb' fill that libsodium's allocator writes into every allocation. Unbound would then iterate over the number of cert files, not the actual slots, so it walks into a slot with garbage data filled with '0xdb' bytes. Any unauthenticated client that
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Unbound","vendor":"NLnet Labs","versions":[{"lessThan":"1.25.2","status":"affected","version":"1.7.0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:7cc9dff0cecb25bfc901a27ffdb769d4423cdf0239a4963e2d02f82f09eef36f · sha256:ebc51a0e5a759466… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"baseScore":5.9,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:7cc9dff0cecb25bfc901a27ffdb769d4423cdf0239a4963e2d02f82f09eef36f · sha256:ebc51a0e5a759466… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-457","description":"CWE-457: Use of Uninitialized Variable","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:7cc9dff0cecb25bfc901a27ffdb769d4423cdf0239a4963e2d02f82f09eef36f · sha256:ebc51a0e5a759466… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["vendor-advisory"],"url":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55990.txt"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:7cc9dff0cecb25bfc901a27ffdb769d4423cdf0239a4963e2d02f82f09eef36f · sha256:ebc51a0e5a759466… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.