TLS Misconfiguration Affects NSD by NLnet Labs
CVE-2026-12490

8.2HIGH

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-12490?

A misconfiguration in NSD's handling of TLS-authenticated requests could expose systems to risk during data transfers. Specifically, when using the provide-xfr command with a tls-auth-name, the requesting secondary must present a client certificate that matches the specified name. Surprisingly, the system allows requests over the standard TLS port or regular TCP port without this client certificate if other conditions are met. This situation creates a potential security gap that could be exploited by malicious entities, emphasizing the need for administrators to review their configurations and ensure secure practices are enforced.

Affected Version(s)

NSD 4.10.1 < 4.14.3

References

CVSS V4

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang from Palo Alto Networks
.