PT-2026-63387 · Nlnet · Unbound
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
NLnet Labs Unbound versions 1.6.0 through 1.25.1
Description
The
view local data and view local datas commands of unbound-control create a bare local zones tree for a configured named view that initially contains no local data. This process fails to include default-protected zones, such as RFC 1918 reverse, AS112 zones, .onion, and .localhost. Consequently, queries for these default-protected names from clients mapped to that view are forwarded to the public DNS via the iterator rather than being handled locally, which bypasses local policy expectations.Recommendations
Update NLnet Labs Unbound to a version later than 1.25.1.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Unbound