DNSSEC Vulnerability in NLnet Labs Unbound Affects Multiple Versions
CVE-2026-46582
3.7LOW
What is CVE-2026-46582?
A vulnerability in NLnet Labs Unbound versions 1.6.0 to 1.25.1 allows for a DNS cache poisoning exploit through the improper handling of a wildcard rrset. A replay attack can lead to the injection of a secure status into an expired record, enabling malicious modification of DNS responses. This occurs when Unbound receives a signed wildcard rrset, which can be mistakenly treated as secure during a brief validation window. Consequently, an attacker can manipulate DNS queries to return altered records, putting systems relying on DNS resolution at risk.
Affected Version(s)
Unbound 1.6.0 < 1.25.2
