DNSSEC Vulnerability in NLnet Labs Unbound Affects Multiple Versions
CVE-2026-46582

3.7LOW

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-46582?

A vulnerability in NLnet Labs Unbound versions 1.6.0 to 1.25.1 allows for a DNS cache poisoning exploit through the improper handling of a wildcard rrset. A replay attack can lead to the injection of a secure status into an expired record, enabling malicious modification of DNS responses. This occurs when Unbound receives a signed wildcard rrset, which can be mistakenly treated as secure during a brief validation window. Consequently, an attacker can manipulate DNS queries to return altered records, putting systems relying on DNS resolution at risk.

Affected Version(s)

Unbound 1.6.0 < 1.25.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.