[UPDATE] [medium] Unbound: Vulnerability allows file manipulation
An attacker from an adjacent network can exploit a vulnerability in Unbound to manipulate the cache, potentially leading to domain hijacking.
CSIRTS triage
- What
- A vulnerability allows file manipulation.
- Who is affected
- An attacker from an adjacent network can exploit this vulnerability in Unbound.
- Urgency
- Remediation is medium urgency due to the potential for domain hijacking.
- Action
- Update Unbound to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Unbound
Get an email when a new Unbound advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2386
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-114110.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-11411 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Unbound
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…nvd · 2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…nvd · 2026-08-01
- mediumGHSA-6hxr-mr5r-9836: re2: Global `String.prototype.match` with an empty-matchable pattern never advances → inf…ghsa · 2026-07-31
- highGHSA-88fw-v6x4-3f58: Spring Data: Unbounded property-path cache keyed by externally-supplied path stringghsa · 2026-07-31
- mediumCVE-2026-52857: Wings is the server control plane for Pterodactyl, a free, open-source game server management …nvd · 2026-07-31
- highCVE-2026-16308: IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quark…nvd · 2026-07-30
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31