Impact
Unbound 1.6.0 through 1.25.1 may accept a replayed signed wildcard DNS record set that omits its required NSEC record, storing it as secure because the RRSIG validates. When a serve‑expired request processes the cached entry, the replayed wildcard can overwrite a sibling record, causing the resolver to return a poisoned answer that redirects clients to an attacker‑controlled host. This flaw permits DNS cache poisoning, a classic vulnerability identified as CWE‑358.
Affected Systems
NLnet Labs Unbound DNS resolver versions 1.6.0 up to and including 1.25.1 are affected. The issue is triggered only when the serve‑expired cache path is enabled, so environments that rely on that feature must be inspected. All systems running an affected Unbound instance and resolving DNSSEC‑signed zones containing wildcard records are potentially impacted.
Risk and Exploitability
CVSS score 3.7 places the flaw in the low‑severity category, and an EPSS score of less than 1 % indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog at present. Exploitation would require an attacker to deliver a specially crafted DNSSEC‑signed response without the NSEC record, most likely over the public network. Successful attacks could manipulate how a specific record resolves, but they do not provide arbitrary code execution or system control.
OpenCVE Enrichment