Echo: unbound: security update to 1.26.1

high Tenable Self-Hosted Container Security Plugin ID 462574

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Novel vulnerabilities to launch algorithmic complexity attacks on DNSSEC have been researched under the
term 'ReTrap'. These result in degradation of service when malicious zones are used to serve the
algorithmic complexity vulnerabilities. NLnet Labs Unbound up to and including 1.26.0 is vulnerable to
some of them. TagTrap, where the triple(Zone, Algo, KeyTag) matching mechanism introduces a significant
attack vector when resolvers handle malicious responses containing numerous mismatched DNSKEY, RRSIG, and
DS record. DelegationTrap, where constructing the chain-of-trust requires iterative validation of DNSKEY
and DS records from the root zone downward. For deeply nested domains, this results in significant
computational overhead. NsecTrap, where responses with excessive invalid NSEC records compel the resolver
to validate each one. AdditionalTrap, where Unbound by default would try to DNSSEC validate the ADDITIONAL
section as well. This can be exploited to waste validation resources by malicious users. (CVE-2026-85501)

Solution

Update the unbound library and its related packages to version 1.26.1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-85501

Plugin Details

Severity: High

ID: 462574

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.66

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-85501

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-85501

IAVA: 2026-A-1070