# CVE-2025-5994

## Summary

- **CVE ID:** CVE-2025-5994
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/R:U/V:C)
- **CWE:** CWE-349
- **Published:** Jul 16, 2025
- **Last Modified:** Mar 13, 2026

## Description

A multi-vendor cache poisoning vulnerability named 'Rebirthday Attack' has been discovered in caching resolvers that support EDNS Client Subnet (ECS). Unbound is also vulnerable when compiled with ECS support, i.e., '--enable-subnet', AND configured to send ECS information along with queries to upstream name servers, i.e., at least one of the 'send-client-subnet', 'client-subnet-zone' or 'client-subnet-always-forward' options is used. Resolvers supporting ECS need to segregate outgoing queries to accommodate for different outgoing ECS information. This re-opens up resolvers to a birthday paradox attack (Rebirthday Attack) that tries to match the DNS transaction ID in order to cache non-ECS poisonous replies.

## Affected Products

- NLnet Labs — Unbound (1.6.2)

## References

- [CNA](https://nlnetlabs.nl/downloads/unbound/CVE-2025-5994.txt)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/08/msg00019.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.20%
- **EPSS Percentile:** 9.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._