Unbound 1.18.0-1.25.1 Proxy-Protocol Cookie Replay (RFC9018)
CVE-2026-54478 Published on July 22, 2026
DNS Cookie bypass when combined with proxy-protocol use
In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie obtained through a given proxy node therefore validates for every PROXYv2-declared source behind that node. On a UDP+proxy-protocol front, an off-path attacker can harvest one cookie with a single legitimate query, then replay it under any spoofed source and pass DNS Cookie checks that were deployed to defeat this in the first place.
Timeline
Issue reported by Qifan Zhang
NLnet Labs shares patch 25 days later.
Qifan Zhang verifies patch 1 day later.
Fixes released with version 1.25.2 53 days later.
Weakness Type
Authentication Bypass by Spoofing
This attack-focused weakness is caused by improperly implemented authentication schemes that are subject to spoofing attacks.
Affected Versions
NLnet Labs Unbound:- Version 1.18.0 and below 1.25.2 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.