DNS Rewriting Vulnerability in NLnet Labs Unbound Product
CVE-2026-50243
What is CVE-2026-50243?
A vulnerability exists in NLnet Labs Unbound, affecting versions 1.6.2 through 1.25.1. It arises when the 'respip' module is utilized in conjunction with 'response-ip' redirect rules or RPZ files containing RPZ-IP triggers. The system fails to adequately verify the security status of upstream responses, allowing the rewriting of potentially BOGUS A/AAAA records. Consequently, if the validator detects an invalid RRSIG on such a record, it is still processed and rewritten to reflect a security status of INSECURE, diverting traffic to an operator's chosen IP address. This behavior can be exploited by malicious actors capable of crafting deceptive DNS responses, creating a serious risk of delivering insecure answers to clients based on operator-configured redirects.
Affected Version(s)
Unbound 1.6.2 < 1.25.2
