A vulnerability classified as very critical was found in NLnet Labs Unbound up to 1.25.1. Impacted is the function query_dname_tolower of the component Wire Format Parser. Executing a manipulation can lead to heap-based buffer overflow.

The identification of this vulnerability is CVE-2026-56416. The attack may be launched remotely. There is no exploit available.