PT-2026-93369 · Nlnet · Unbound

·

CVE-2026-77955

·

Published

2026-09-16

·

Updated

2026-09-29

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.13.2 through 1.26.1
Description Zones configured with zonemd-check: yes that are located below a trust anchor contain a flaw where tampered zone contents may be served or stored to disk before the ZONEMD integrity check is completed. This occurs due to the asynchronous resolution of DS/DNSKEY records required for the check. If the zonefile: option is used to write a zonefile to disk while the ZONEMD check fails, the tampered data is reloaded upon startup and remains available until the next verification concludes. Even if verification subsequently fails, the tampered data persists on disk for future reloads.
Recommendations Update NLnet Labs Unbound to a version later than 1.26.1. As a temporary mitigation, avoid using the zonefile: option for zones configured with zonemd-check: yes that are located below a trust anchor.

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-101715
CVE-2026-77955
ECHO-D671-FE45-3358
OPENSUSE-SU-2026:11930-1

Affected Products

Unbound