PT-2026-63373 · Nlnet · Unbound

·

CVE-2026-42955

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.16.2 through 1.25.1
Description An issue exists within the ghost domain names family of attacks where an adversary controlling a ghost zone can extend the ghost domain window for A/AAAA glue records. By sending a single client A/AAAA query, the attacker can cause the system to overwrite the cached expired parent-side glue rrset, extending the window by up to one cached TTL configured value, specifically the cache-max-ttl variable. In configurations where harden-referral-path: yes is enabled, the issue can be triggered without a client query as the system performs the query implicitly.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92964
CVE-2026-42955
ECHO-5B87-58C9-5E30
OESA-2026-3434
OESA-2026-3435
OESA-2026-3436
OESA-2026-3437
OESA-2026-3438
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound