{"affected":[{"affectedData":[{"defaultStatus":"unaffected","product":"Unbound","vendor":"NLnet Labs","versions":[{"lessThan":"1.26.1","status":"affected","version":"0","versionType":"semver"}]}],"source":"sep@nlnetlabs.nl"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*","matchCriteriaId":"EFE466C2-2830-48B5-AD1D-0138CB8207A7","versionEndExcluding":"1.26.1","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"In NLnetLabs Unbound up to and including 1.26.0, a degradation of service vulnerability is present in the TCP/DoT reading procedure where there is no limit on consecutive reads. A malicious actor that can stream and sustain a rate of distinct uncached names over the TCP/DoT connection, monopolizes a single worker's entire event loop for as long as its writes stay ahead of the drain."}],"id":"CVE-2026-80225","lastModified":"2026-09-23T19:57:08.517","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":5.3,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","version":"3.1"},"exploitabilityScore":3.9,"impactScore":1.4,"source":"sep@nlnetlabs.nl","type":"Secondary"},{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"exploitabilityScore":3.9,"impactScore":3.6,"source":"nvd@nist.gov","type":"Primary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-80225","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-16T14:32:57.188145Z","version":"2.0.3"}}]},"published":"2026-09-16T09:17:06.100","references":[{"source":"sep@nlnetlabs.nl","tags":["Patch","Vendor Advisory"],"url":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-80225.txt"}],"sourceIdentifier":"sep@nlnetlabs.nl","vulnStatus":"Analyzed","weaknesses":[{"description":[{"lang":"en","value":"CWE-770"}],"source":"sep@nlnetlabs.nl","type":"Secondary"}]}