PT-2026-63378 · Nlnet · Unbound

·

CVE-2026-46582

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.6.0 through 1.25.1
Description A flaw exists where a replay of a wildcard rrset (Resource Record Set) can be briefly marked as DNSSEC secure based solely on RRSIG (Resource Record Signature) validation and stored in the cache before NSEC (Next Secure) validation identifies it as bogus. This occurs when a resolving thread marks an rrset as secure and another thread on the serve expired path retrieves these updated contents for a reply. An attacker can exploit this to change a specific record adjacent to a wildcard into that wildcard. This is achieved by using a DNSSEC-signed domain and a CNAME wrapper record pointing to a record next to a wildcard. By querying for the wildcard sibling record and later injecting a wildcard replay into a response for the CNAME wrapper after expiry, the poisoned rrset is marked secure and points to the wildcard. This issue specifically affects the serve expired path and requires the injection of a signed wildcard rrset without the accompanying NSEC rrset.
Recommendations Update NLnet Labs Unbound to a version later than 1.25.1.

Fix

Improperly Implemented Security Check for Standard

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92961
CVE-2026-46582
ECHO-6F41-EC39-7F1E
OESA-2026-3333
OESA-2026-3334
OESA-2026-3335
OESA-2026-3336
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound