SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-50248

MEDIUM · CVSS 6.5 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

NLnet Labs Unbound versions 1.7.0 through 1.25.1 are vulnerable to a flaw that allows an attacker to spoof a hostname's A/AAAA record, potentially designating themselves as a primary transfer (XFR) endpoint for an auth/rpz zone. This could enable the attacker to replace the entire zone or modify the resolver's response policy, leading to significant disruptions in DNS resolution. Organizations using affected versions of Unbound should prioritize patching to mitigate the risk of unauthorized DNS manipulation.

CVE
CVE-2026-50248
Severity
MEDIUM
CVSS
6.5
EPSS
0.13%

Original NVD Description

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.

Related CVEs

Other vulnerabilities affecting the same vendor(s)