CVE & CISA-KEV Catalog

CVE-2026-50252

MEDIUM
9.3
CVSS v3
NVD

Description

In NLnet Labs Unbound 1.4.22 up to and including 1.25.1, UDP source port is randomized and intended to serve as a secret value that increases the entropy of DNS transactions. When resolver load balancing policies depend on the source port while their outcome is revealed this secrecy is undermined. The vulnerability arises when the load balancing policy is consistent with respect to the incoming source UDP port and IP address while heavily depending on the incoming source UDP port as a randomization source. When the SO_REUSEPORT configuration option is enabled ('so-reuseport: yes') in Unbound (by default), it meets these conditions, making it vulnerable for DNS cache poisoning attacks. Upon startup, Unbound randomly partitions the available UDP source port space into disjoint subsets of (almost) equal size, assigning each subset to a specific worker thread. When an incoming DNS query is received, the kernel’s SO_REUSEPORT load balancing mechanism deterministically assigns the query to a socket associated with a particular thread. All outgoing DNS queries generated during the resolution of that request use source ports selected exclusively from the port subset assigned to the corresponding thread. Since these port subsets are disjoint across threads, the source port observed in a resolver’s outgoing query to an authoritative name server serves as a reliable indicator of the worker thread that processed the original client query. A malicious actor can acquire the mapping between incoming UDP source ports (for a given fixed source IP address) and Unbound worker threads and leverage it to conduct DNS cache poisoning attacks by effectively lowering the random port population per thread.

How to fix

Remediation Available
unboundDebian
Fixed in:1.26.1-0+deb13u1CVE-2026-50252
Fixed in:1.25.2-1CVE-2026-50252
python3-unboundRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
python3-unboundRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
python3-unbound-debuginfoRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
python3-unbound-debuginfoRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unboundRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unboundRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-anchorRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
unbound-anchorRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
unbound-anchor-debuginfoRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
unbound-anchor-debuginfoRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
unbound-debuginfoRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-debuginfoRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-debugsourceRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-debugsourceRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-develRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-develRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-dracutRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-dracutRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-libsRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-libsRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-libs-debuginfoRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-libs-debuginfoRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
Fixed in:0:1.24.2-3.el9_8.6RHSA-2026:68292
unbound-utilsRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
unbound-utilsRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
unbound-utils-debuginfoRocky
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
unbound-utils-debuginfoRed Hat / RHEL
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291
Fixed in:0:1.24.2-7.el10_2.5RHSA-2026:68291

This vulnerability affects an unusually large number of packages. The highest-confidence fixes are shown above; the full list is longer. Check the referenced advisories for complete coverage.

TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorAdjacent
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeChanged

Impact

ConfidentialityNone
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

Exploit Intelligence

0.16%probability of exploitation in 30 days
6thpercentile

Low risk: more likely to be exploited than 6% of all known CVEs.

References

Vendor Advisory1

Related Vulnerabilities

Other CWE-349 vulnerabilities, ordered by exploit likelihood. View all

CVESeverityCVSSEPSSExploitedFix
CVE-2019-9535Critical9.82.5%--
CVE-2026-32162High8.41.9%-Fix
CVE-2018-1131High8.81.3%--
CVE-2021-21374High8.11.0%-Fix
CVE-2024-21094Low3.70.8%-Fix
CVE-2025-40778High8.60.7%-Fix

Common questions

How do I fix CVE-2026-50252?

Published advisories record a fix for 27 affected products. The "How to fix" section on this page lists the fixed version and source advisory for each one, so apply the entry matching what you actually run.

Is CVE-2026-50252 being actively exploited?

Not that we know of. CVE-2026-50252 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 0.16% is the estimated probability that it will be exploited in the next 30 days. That is higher than 6% of all scored CVEs.

How severe is CVE-2026-50252?

CVE-2026-50252 has a CVSS v3 base score of 9.3, rated moderate. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.

What does CVE-2026-50252 affect?

Published advisories record a fix for unbound (Debian), python3-unbound (Red Hat / RHEL), python3-unbound (Rocky), python3-unbound-debuginfo (Red Hat / RHEL), and 23 more. Only products with a sourced advisory are listed, so treat this as what we can cite rather than a complete inventory.

Embed a live status badge for CVE-2026-50252
CVE-2026-50252 severity badge

Markdown

[![CVE-2026-50252](https://tridentstack.com/cve/badge/CVE-2026-50252.svg)](https://tridentstack.com/cve/CVE-2026-50252)

HTML

<a href="https://tridentstack.com/cve/CVE-2026-50252"><img src="https://tridentstack.com/cve/badge/CVE-2026-50252.svg" alt="CVE-2026-50252"></a>

Check your Linux endpoints for this class of vulnerability

TridentStack Control continuously scans Linux endpoints for known vulnerabilities and deploys the fixes from the same console. 200 endpoints free forever, no credit card.

Patch your fleet freeStart freeThis CVE lookup is free and always will be.

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-07-24.