Ghost Domain Name Vulnerability in Unbound by NLnet Labs
CVE-2026-40622

6.6MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-40622?

Unbound, a DNS resolver maintained by NLnet Labs, contains a vulnerability allowing attackers to exploit ghost domain names. This issue arises when an adversary controls a ghost zone and queries a vulnerable version of Unbound. The results can lead to the overwriting of cached expired parent-side referral NS records with the child-side apex records, effectively extending the ghost domain window by the cached TTL value. In specific configurations utilizing 'harden-referral-path: yes', this vulnerability can be triggered without a direct NS query, as Unbound performs it implicitly. The vendor has released version 1.25.1 to address this vulnerability, preventing the extension of TTLs for parent NS records irrespective of their trust level.

Affected Version(s)

Unbound 1.16.2 < 1.25.1

References

CVSS V4

Score:
6.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.