TLS Misconfiguration Affects NSD by NLnet Labs
CVE-2026-12490
8.2HIGH
What is CVE-2026-12490?
A misconfiguration in NSD's handling of TLS-authenticated requests could expose systems to risk during data transfers. Specifically, when using the provide-xfr command with a tls-auth-name, the requesting secondary must present a client certificate that matches the specified name. Surprisingly, the system allows requests over the standard TLS port or regular TCP port without this client certificate if other conditions are met. This situation creates a potential security gap that could be exploited by malicious entities, emphasizing the need for administrators to review their configurations and ensure secure practices are enforced.
Affected Version(s)
NSD 4.10.1 < 4.14.3
