CVE-2025-11411
Unbound vulnerability analysis and mitigation

Overview

CVE-2025-11411 affects NLnet Labs Unbound up to and including version 1.24.0. The vulnerability was discovered and disclosed by researchers from Tsinghua University on October 22, 2025. The vulnerability allows possible domain hijack attacks through promiscuous NS RRSets that complement positive DNS replies in the authority section, which can be used to trick resolvers to update their delegation information for the zone (NVD, Unbound Advisory).

Technical details

The vulnerability exists in the handling of NS RRSets in DNS replies. A malicious actor can exploit this by injecting NS RRSets and their respective address records in a reply through methods such as packet spoofing or fragmentation attacks. Unbound would proceed to update the NS RRSet data it already has since the new data has enough trust for it as in-zone data for the delegation point. The vulnerability has been assigned a CVSS v4.0 score of 5.7 (Medium) with vector CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:H/E:P (NVD).

Impact

The vulnerability can lead to domain hijacking attacks where attackers can manipulate the resolver's delegation information for a zone. This affects the resolver's knowledge of the zone's name servers, potentially redirecting DNS queries to malicious servers (Unbound Advisory).

Mitigation and workarounds

The vulnerability has been fixed in Unbound version 1.24.1, which includes a patch that scrubs unsolicited NS RRSets and their respective address records from replies. Users can either upgrade to version 1.24.1 or apply one of two available patches: a full patch that includes all updates including tests and documentation, or a minimal patch that only includes the necessary code changes (Unbound Advisory).

Additional resources


SourceThis report was generated using AI

Related Unbound vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-5994HIGH8.7
  • UnboundUnbound
  • unbound-libs-debuginfo
NoYesJul 16, 2025
CVE-2024-33655HIGH7.5
  • UnboundUnbound
  • unbound-anchor
NoYesJun 06, 2024
CVE-2024-1931HIGH7.5
  • NixOSNixOS
  • unbound-python
NoYesMar 07, 2024
CVE-2025-11411MEDIUM5.7
  • UnboundUnbound
  • unbound
NoYesOct 22, 2025
CVE-2024-8508MEDIUM5.3
  • NixOSNixOS
  • unbound-devel
NoYesOct 03, 2024

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management