PT-2026-63387 · Nlnet · Unbound

·

CVE-2026-55708

·

Published

2026-07-22

·

Updated

2026-08-31

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.6.0 through 1.25.1
Description The view local data and view local datas commands of unbound-control create a bare local zones tree for a configured named view that initially contains no local data. This process fails to include default-protected zones, such as RFC 1918 reverse, AS112 zones, .onion, and .localhost. Consequently, queries for these default-protected names from clients mapped to that view are forwarded to the public DNS via the iterator rather than being handled locally, which bypasses local policy expectations.
Recommendations Update NLnet Labs Unbound to a version later than 1.25.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92934
CVE-2026-55708
ECHO-2666-6303-C7A7
OESA-2026-3333
OESA-2026-3334
OESA-2026-3335
OESA-2026-3336
OESA-2026-3436
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1
SUSE-SU-2026:3884-1
SUSE-SU-2026:3885-1

Affected Products

Unbound