Data Element containing Pointer Item without Proper Copy Control Element Affecting unbound package, versions [1.25.0,1.25.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.24% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-UNBOUND-18507939
  • published2 Aug 2026
  • disclosed22 Jul 2026
  • creditUnknown

Introduced: 22 Jul 2026

NewCVE-2026-52863  (opens in a new tab)
CWE-1098  (opens in a new tab)

How to fix?

Upgrade unbound to version 1.25.2 or higher.

Overview

Affected versions of this package are vulnerable to Data Element containing Pointer Item without Proper Copy Control Element in the process when specific, non-default configurations are enabled, including the use of respip or rpz modules, subquery attachment features, and access-control-view, particularly under heavy server load. An attacker can cause the server to crash by triggering memory corruption through crafted DNS queries. This is only exploitable if the server is configured with the aforementioned modules and features enabled simultaneously under high load conditions.

Workaround

This vulnerability can be mitigated by disabling the combination of 'respip' or 'rpz' modules, subquery attachment features (such as respip CNAME redirection, dns64, or subnetcache), and 'access-control-view' if not strictly required. Restarting the service after configuration changes is necessary.

CVSS Base Scores

version 4.0
version 3.1