DNS Resolver Vulnerability in NLnet Labs Unbound Software
CVE-2026-50248
6.5MEDIUM
What is CVE-2026-50248?
A vulnerability exists in NLnet Labs' Unbound software versions 1.7.0 to 1.25.1 involving the handling of authoritative zone configurations. If a primary hostname in an authority or response policy zone resolves to an invalid BOGUS A/AAAA record, the software may still treat it as a possible zone transfer (XFR) destination. This flaw allows a malicious actor who can spoof the A/AAAA records to potentially assume control over the zone's primary XFR endpoint, leading to a risk of unauthorized zone replacements and manipulation of the resolver's entire response policy.
Affected Version(s)
Unbound 1.7.0 < 1.25.2
