DNSSEC Bypass Vulnerability in NLnet Labs Unbound
CVE-2026-44687

3.7LOW

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-44687?

A vulnerability in NLnet Labs Unbound, present in versions 1.13.2 to 1.25.1, allows for a DNSSEC bypass due to an off-by-one error in the 'harden-below-nxdomain' logic. This flaw affects stub or forward zones where the domain name is positioned below an intermediate label within a DNSSEC signed zone. As a result, secure NXDOMAIN responses from the parent zone can shadow the intended stub/forward zone configuration, preventing proper DNS resolution by bypassing the contact with the configured upstream servers. The vulnerability is triggered by queries directed at these intermediate labels, which can lead to improper handling of DNS requests and cache poisoning risks.

Affected Version(s)

Unbound 1.13.2 < 1.25.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.