CVE-2025-5994

Cache poisoning via the ECS-enabled Rebirthday Attack

Description

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-client-subnet', 'client-subnet-zone' or 'client-subnet-always-forward' options is used. Resolvers supporting ECS need to segregate outgoing queries to accommodate for different outgoing ECS information. This re-opens up resolvers to a birthday paradox attack (Rebirthday Attack) that tries to match the DNS transaction ID in order to cache non-ECS poisonous replies.

Remediation

Solution:

  • This issue is fixed in 1.23.1 and all later versions. Not using EDNS Client Subnet (ECS) is also a mitigation for affected versions.

Category

8.7
CVSS
Severity: High
CVSS 4.0 •
EPSS 0.02%
Vendor Advisory nlnetlabs.nl
Affected: NLnet Labs Unbound
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2025-5994?
CVE-2025-5994 has been scored as a high severity vulnerability.
How to fix CVE-2025-5994?
To fix CVE-2025-5994: This issue is fixed in 1.23.1 and all later versions. Not using EDNS Client Subnet (ECS) is also a mitigation for affected versions.
Is CVE-2025-5994 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2025-5994 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2025-5994?
CVE-2025-5994 affects NLnet Labs Unbound.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.