PT-2026-64166 · Debian+1 · Knot

CVE-2026-39155

·

Published

2026-07-23

·

Updated

2026-07-23

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Knot DNS versions prior to 3.4.10 Knot DNS versions 3.5.x prior to 3.5.4
Description A flaw exists in the mod-onlinesign module where the next NSEC owner name is computed incorrectly. This error creates an overly broad authenticated denial interval, which enables downstream validating resolvers that utilize aggressive negative caching to synthesize negative responses for legitimate names, resulting in a resolver-side denial of service.
Recommendations Update Knot DNS to version 3.4.10 or later. Update Knot DNS to version 3.5.4 or later.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39155

Affected Products

Knot