Junglewise Threat Intelligence

CVE-2026-54478: NLnet Labs Unbound DNS Cookie authentication bypass in PROXYv2

CVE-2026-54478 · Severity: low · CVSS 3.7 · Published 2026-07-22

Technologies: NLnet Labs Unbound. Vendors: NLnet Labs.

Executive brief

A vulnerability in the Unbound DNS resolver could allow attackers to bypass security checks designed to prevent identity spoofing. When the software is configured to use specific proxy and cookie settings, it incorrectly identifies the source of a request, allowing an attacker to reuse a security token for multiple spoofed identities. This undermines protections against DNS-based attacks like amplification or cache poisoning.

Technical details

A vulnerability exists in NLnet Labs Unbound (versions 1.18.0 through 1.25.1) when configured with 'proxy-protocol-port' and 'answer-cookie: yes'. The RFC 9018 server-cookie SipHash is incorrectly computed using the proxy's wire address rather than the PROXYv2-declared client IP. This flaw allows an off-path network attacker to obtain a valid server cookie via a legitimate query and then replay that cookie with spoofed source IP addresses. This effectively bypasses DNS Cookie checks intended to prevent IP spoofing. The issue is resolved in Unbound version 1.25.2.

Affected products

  • NLnet Labs Unbound 1.18.0 to 1.25.1

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory
  • 2026-07-22: patched: Fixed in version 1.25.2

References

Related threats