CVE-2025-5994 | NLnet Labs Unbound up to 1.22.x DNS Transaction ID acceptance of extraneous untrusted data with trusted data (EUVD-2025-21730 / Nessus ID 242937)
A vulnerability, which was classified as problematic, has been found in NLnet Labs Unbound up to 1.22.x. This issue affects some unknown processing of the component DNS Transaction ID Handler. This manipulation causes acceptance of extraneous untrusted data with trusted data.
The identification of this vulnerability is CVE-2025-5994. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.