DNSSEC Bypass Vulnerability in NLnet Labs Unbound
CVE-2026-44687
3.7LOW
What is CVE-2026-44687?
A vulnerability in NLnet Labs Unbound, present in versions 1.13.2 to 1.25.1, allows for a DNSSEC bypass due to an off-by-one error in the 'harden-below-nxdomain' logic. This flaw affects stub or forward zones where the domain name is positioned below an intermediate label within a DNSSEC signed zone. As a result, secure NXDOMAIN responses from the parent zone can shadow the intended stub/forward zone configuration, preventing proper DNS resolution by bypassing the contact with the configured upstream servers. The vulnerability is triggered by queries directed at these intermediate labels, which can lead to improper handling of DNS requests and cache poisoning risks.
Affected Version(s)
Unbound 1.13.2 < 1.25.2
