Repository navigation
CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7 #474
Copy link
Copy link
Open
Labels
Mend: dependency security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
Description
Activity
- addedMend: dependency security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
on Jul 23, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4[/+]on Jul 23, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4[/-][+]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 19, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4[/+]on Aug 19, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4[/-][+]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 19, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4[/+]on Aug 21, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4[/-][+]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 26, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4[/+]on Aug 26, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4[/-][+]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 27, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4[/+]on Aug 27, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4[/-][+]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 27, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4[/+]on Aug 27, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4[/-][+]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Aug 28, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4[/+]on Aug 28, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4[/-][+]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Sep 4, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4[/+]on Sep 4, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4[/-][+]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Sep 17, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4[/+]on Sep 17, 2026 - changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4[/-][+]CVE-2026-56444 (Medium) detected in src4.0.4 - autoclosed[/+]on Sep 18, 2026 mend-bolt-for-github commented
on Sep 18, 2026 ContributorAuthorMore actions✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
mend-bolt-for-github commented
on Sep 18, 2026 ContributorAuthorMore actions✔️ This issue was automatically closed by Mend because the vulnerable library in the specific branch(es) was either marked as ignored or it is no longer part of the Mend inventory.
- changed the title
[-]CVE-2026-56444 (Medium) detected in src4.0.4 - autoclosed[/-][+]CVE-2026-56444 (Medium) detected in freebsd-srcrelease/15.0.0-p7[/+]on Oct 7, 2026 mend-bolt-for-github commented
on Oct 7, 2026 ContributorAuthorMore actionsℹ️ This issue was automatically re-opened by Mend because the vulnerable library in the specific branch(es) has been detected in the Mend inventory.
Metadata
Metadata
Assignees
Labels
Mend: dependency security vulnerabilitySecurity vulnerability detected by WhiteSourceSecurity vulnerability detected by WhiteSource
CVE-2026-56444 - Medium Severity Vulnerability
The FreeBSD src tree publish-only repository. Experimenting with 'simple' pull requests....
Library home page: https://github.com/freebsd/freebsd-src.git
Found in base branches: stable/4.0, master
In NLnet Labs Unbound 1.20.0 up to and including 1.25.1, when Unbound is configured with 'serve-expired: yes' and 'serve-expired-client-timeout > discard-timeout > 0' (contrary to the suggested values), the discard-timeout branch during the serve expired logic drops an aged client reply without performing the correct accounting for the number of reply addresses for the query. Other identical branches outside of serve expired perform the correct decrement. Since the counter is never decremented in such scenario, it can reach the maximum limit and new clients for duplicate in-flight queries are silently dropped resulting in degradation of resolution service. A malicious actor can exploit the vulnerability by querying the resolver for a client-controlled slow-on-demand authoritative zone that can drive the counter past the threshold. Shipped defaults for 'serve-expired-client-timeout: 1800' and 'discard-timeout: 1900' make the branch unreachable.
Publish Date: 2026-07-22
URL: CVE-2026-56444
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with Mend here