PT-2026-63377 · Nlnet+1 · Unbound+1

·

CVE-2026-44690

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.7.0 through 1.25.1
Description Insufficient validation of the RRSIG.Labels field and premature cache writes during RFC 8198 aggressive NSEC processing enable cache poisoning. An attacker controlling a single delegated zone under an NSEC-signed parent domain can poison arbitrary sibling zones. By using fraudulent wildcard DS records with fewer labels than expected or an unknown algorithm, the attacker can create insecure existence for non-existent delegations covered by the parent's NSEC chain, allowing the injection of insecure wildcard records for those delegations.
Recommendations Update NLnet Labs Unbound to a version later than 1.25.1.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:55784
ALSA-2026:55841
ALSA-2026:55892
AZL-92931
CVE-2026-44690
ECHO-E154-63C5-79FE
OESA-2026-3333
OESA-2026-3334
OESA-2026-3335
OESA-2026-3336
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
RHSA-2026:55784
RHSA-2026:55841
RHSA-2026:55892
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Rocky Linux
Unbound