{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/libunbound/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":5.9,"id":"CVE-2026-44621"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Libunbound"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability","libunbound"],"_cs_type":"advisory","_cs_vendors":["NLnet Labs"],"content_html":"\u003cp\u003eCVE-2026-44621 details a denial-of-service vulnerability impacting applications that leverage the Libunbound DNS resolver library. This issue specifically arises when Libunbound applications are configured with the \u003ccode\u003eunwanted-reply-threshold\u003c/code\u003e option. Under certain conditions, processing maliciously crafted or unusual DNS replies can lead to the gradual degradation of the application's stability, eventually causing it to terminate abruptly. This vulnerability, disclosed by the Microsoft Security Response Center, highlights a potential risk to the availability and stability of services relying on affected Libunbound versions for DNS resolution. The public advisory does not detail the precise trigger mechanisms or the volume or nature of replies required for successful exploitation, but the consequence is a critical disruption to the application's function. Defenders should prioritize identifying Libunbound deployments within their infrastructure and monitoring for updates.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-44621 leads to an abrupt termination of the affected Libunbound application. This results in a denial-of-service condition, rendering services dependent on Libunbound's DNS resolution unavailable or unreliable. Organizations using vulnerable versions of Libunbound, particularly those with the \u003ccode\u003eunwanted-reply-threshold\u003c/code\u003e configured, face a risk of service interruption, which could lead to operational downtime, loss of revenue, and reputational damage depending on the criticality of the affected application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor the official channels of NLnet Labs and Microsoft Security Response Center for further details and security updates related to CVE-2026-44621.\u003c/li\u003e\n\u003cli\u003eReview configurations of all Libunbound applications within your environment to identify instances utilizing the \u003ccode\u003eunwanted-reply-threshold\u003c/code\u003e option.\u003c/li\u003e\n\u003cli\u003eConsider disabling the \u003ccode\u003eunwanted-reply-threshold\u003c/code\u003e option if its operational impact outweighs the risk of this denial-of-service vulnerability, after proper assessment and testing.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T07:28:10Z","date_published":"2026-07-23T07:28:10Z","id":"https://feed.craftedsignal.io/briefs/2026-07-libunbound-dos/","summary":"CVE-2026-44621 describes a vulnerability in Libunbound applications where, when configured with the 'unwanted-reply-threshold' option, they can be abruptly terminated, leading to a denial of service.","title":"Libunbound Denial of Service via unwanted-reply-threshold","url":"https://feed.craftedsignal.io/briefs/2026-07-libunbound-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Libunbound","version":"https://jsonfeed.org/version/1.1"}