Vulnerability in ZONEMD Configuration of Unbound by NLnet Labs
CVE-2026-77955
4.4MEDIUM
What is CVE-2026-77955?
A security issue exists in NLnet Labs Unbound versions 1.13.2 through 1.26.1, specifically in ZONEMD configured zones where the integrity check may be bypassed during asynchronous resolution. This vulnerability allows for the potential serving or storage of tampered zone contents that could persist on disk even when integrity verification fails. The ZONEMD check must complete before safely verifying DNSSEC data, and improper handling could lead to incorrect zone data being reloaded on startup.
Affected Version(s)
Unbound 1.13.2 < 1.26.1
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Yuqi Qiu (Nankai University, AOSP Lab)
Xiang Li (Nankai University, AOSP Lab)
Qifan Zhang (Palo Alto Networks)
