Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-80225
NLnet Labs Unbound — Possible degradation of service from continuous queries on the same TCP/DoT connection
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .0048 39.3 —
AFFECTED
Product Versions Fixed
Unbound unspecified —
TIMELINE
Sep 7 Reserved by NLnet Labs
Sep 16 Published (CNA: NLnet Labs)
Sep 23 RESCORED — CVE-2026-80225 (NLnet Labs Unbound). CVSS 5.3 → 7.5 (NVD).
Description
In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| September 7, 2026 | Reserved | Reserved by NLnet Labs |
| September 16, 2026 | Published | Published (CNA: NLnet Labs) |
| September 23, 2026 | RESCORED | RESCORED — CVE-2026-80225 (NLnet Labs Unbound). CVSS 5.3 → 7.5 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| NLnet Labs | Unbound | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-80225 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.