DNS Resolver Vulnerability in NLnet Labs Unbound Software
CVE-2026-50248

6.5MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-50248?

A vulnerability exists in NLnet Labs' Unbound software versions 1.7.0 to 1.25.1 involving the handling of authoritative zone configurations. If a primary hostname in an authority or response policy zone resolves to an invalid BOGUS A/AAAA record, the software may still treat it as a possible zone transfer (XFR) destination. This flaw allows a malicious actor who can spoof the A/AAAA records to potentially assume control over the zone's primary XFR endpoint, leading to a risk of unauthorized zone replacements and manipulation of the resolver's entire response policy.

Affected Version(s)

Unbound 1.7.0 < 1.25.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.