{"id":"AZL-92925","summary":"CVE-2026-50045 affecting package unbound for versions less than 1.25.2-1","details":"In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a single client query for a deeply nested name under a DNSSEC-signed parent can cause Unbound to send more upstream packets per client query than the configured 'max-global-quota'. This effectively bypasses a security configuration that limits upstream amplification traffic.","modified":"2026-08-28T17:47:24.751722619Z","published":"2026-07-22T14:17:19Z","upstream":["CVE-2026-50045"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50045"}],"affected":[{"package":{"name":"unbound","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/unbound"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.25.2-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92925.json"}}],"schema_version":"1.9.0"}