Vulnerability in ZONEMD Configuration of Unbound by NLnet Labs
CVE-2026-77955

4.4MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-77955?

A security issue exists in NLnet Labs Unbound versions 1.13.2 through 1.26.1, specifically in ZONEMD configured zones where the integrity check may be bypassed during asynchronous resolution. This vulnerability allows for the potential serving or storage of tampered zone contents that could persist on disk even when integrity verification fails. The ZONEMD check must complete before safely verifying DNSSEC data, and improper handling could lead to incorrect zone data being reloaded on startup.

Affected Version(s)

Unbound 1.13.2 < 1.26.1

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yuqi Qiu (Nankai University, AOSP Lab)
Xiang Li (Nankai University, AOSP Lab)
Qifan Zhang (Palo Alto Networks)
.