CVE Feed

    Dashboard / CVE / CVE-2026-50248

    CVE-2026-50248

    In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.

    Published:Jul 22, 2026
    Last Modified:Jul 27, 2026
    EPS:Jul 22, 2026
    EPSS Score:0.00133
    CVSS Score:6.5

    Affected Products

    Vendor
    Nlnetlabs
    Product
    Unbound

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High