Description
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.
Published: 2026-07-22
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unbound versions 1.7.0 through 1.25.1 allow a resolver to treat a configured primary hostname for zone transfer as a valid endpoint even when that hostname resolves to a BOGUS A or AAAA record. Because the resolver does not require a valid signature for the primary hostname, an attacker that can spoof the DNS records for that hostname becomes the zone transfer primary. Presented with the attacker‑controlled zone data, the resolver accepts it and replaces its entire response policy zone, effectively allowing a successful zone takeover and policy manipulation.

Affected Systems

NLnet Labs Unbound 1.7.0 and all subsequent releases up to and including 1.25.1 are affected when an authenticated RPZ zone exercises a primary hostname that resolves to a non‑existent address record. Versions 1.25.2 and newer contain the fix and are not vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score of <1% suggests a very low likelihood of exploitation in the wild, yet the vulnerability is publicly documented and could be used if an attacker can influence the DNS for the hostname. Based on the description, it is inferred that controlling or spoofing the primary hostname’s A/AAAA record requires the attacker to have influence over external DNS for that hostname, which may be relatively straightforward in some environments. The vulnerability is not listed in the CISA KEV catalog, and the attack requires no valid RRSIG; thus the exploitation path is primarily via hostname spoofing and unsolicited zone transfer acceptance.

Generated by OpenCVE AI on August 3, 2026 at 23:46 UTC.

Remediation

Vendor Solution

This issue is fixed starting with version 1.25.2


OpenCVE Recommended Actions

  • Upgrade Unbound to version 1.25.2 or later, which fixes the XFR host validation flaw.
  • If upgrading is delayed, block or restrict zone transfer for the affected RPZ zones to known, trusted IP addresses or disable XFR entirely until the patch is applied.
  • Configure Unbound to enforce DNSSEC validation for XFR endpoints, ensuring that only signed records are considered valid primary hostnames.

Generated by OpenCVE AI on August 3, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Nlnetlabs
Nlnetlabs unbound
Vendors & Products Nlnetlabs
Nlnetlabs unbound

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Description In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.
Title BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L'}


Subscriptions

Nlnetlabs Unbound
cve-icon MITRE

Status: PUBLISHED

Assigner: NLnet Labs

Published:

Updated: 2026-07-22T18:58:20.160Z

Reserved: 2026-06-22T10:11:10.539Z

Link: CVE-2026-50248

cve-icon Vulnrichment

Updated: 2026-07-22T18:58:17.138Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T14:17:20.370

Modified: 2026-07-24T13:59:37.787

Link: CVE-2026-50248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:00:09Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity