Description
Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service.
Published: 2026-07-23
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Knot DNS versions before 3.4.10 and before 3.5.4 contain a flaw in the mod‑onlinesign module that incorrectly computes the next NSEC owner name. The incorrect calculation creates an overly broad authenticated denial interval, which downstream resolvers that use aggressive negative caching may treat as a valid negative response. When such a resolver receives a query for a legitimate name, it can be tricked into returning a negative answer, effectively denying legitimate resolution requests and causing a denial‑of‑service condition on the resolver side.

Affected Systems

Knot DNS 3.4.9 and earlier, as well as Knot DNS 3.5.3 and earlier. The vulnerability is present in all releases prior to 3.4.10 and 3.5.4, respectively.

Risk and Exploitability

The CVSS score of 6.5 classifies this as a moderate severity vulnerability, but the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Exploit requires a modifiable query path to a vulnerable Knot DNS server and the presence of a downstream resolver that relies heavily on negative caching. The attack is therefore feasible in environments where resolvers aggressively cache negative responses, but overall risk remains moderate and the window of attack is limited.

Generated by OpenCVE AI on August 3, 2026 at 23:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Knot DNS to version 3.4.10 or later (or 3.5.4 for the 3.5.x branch) to fix the incorrect NSEC calculation.
  • If upgrading is not possible immediately, disable the mod‑onlinesign feature or stop serving signed zones from this Knot instance to eliminate the vulnerability in its current configuration.
  • Configure downstream resolvers to reduce aggressive negative caching for zones served by this Knot server or ensure they respect the correct NSEC chain.

Generated by OpenCVE AI on August 3, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Incorrect NSEC Calculation Leading to Authenticated Denial Interval and Resolver DoS

Sun, 02 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Title Incorrect NSEC Calculation Leading to Authenticated Denial Interval and Resolver DoS

Sat, 01 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Incorrect NSEC Owner Computation in Knot DNS Leading to Denial of Service

Mon, 27 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Incorrect NSEC Owner Computation in Knot DNS Leading to Denial of Service

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-345
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Knot-dns
Knot-dns knot Dns
Vendors & Products Knot-dns
Knot-dns knot Dns

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service.
References

Subscriptions

Knot-dns Knot Dns
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-24T19:35:57.930Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-39155

cve-icon Vulnrichment

Updated: 2026-07-24T19:35:36.823Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T21:17:04.210

Modified: 2026-07-30T19:32:25.133

Link: CVE-2026-39155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:15:04Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity