PT-2026-63382 · Nlnet · Unbound

·

CVE-2026-50248

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.7.0 through 1.25.1
Description An issue exists where an auth/rpz zone with a configured primary hostname that resolves to BOGUS A/AAAA records is still treated as a potential XFR endpoint. XFR (Zone Transfer) is a mechanism used to replicate DNS zone data from a primary server to a secondary server. A malicious actor capable of spoofing the hostname's A/AAAA record, without needing a valid RRSIG, can assume the role of the zone's XFR primary and replace the entire zone or the resolver's complete response policy.
Recommendations Update NLnet Labs Unbound to a version later than 1.25.1.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92928
CVE-2026-50248
ECHO-120D-BA58-FA3D
OESA-2026-3333
OESA-2026-3334
OESA-2026-3335
OESA-2026-3336
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound