Impact
In Unbound 1.6.0 through 1.25.1, the commands "view_local_data" and "view_local_datas" in unbound-control create an empty local zones tree for a configured named view that has no local data. The creation omits the default‑protected zones such as RFC 1918 reverse, AS112, .onion, and .localhost. Consequently, any query for a protected name from a client mapped to that view bypasses the intended local zone handling and is forwarded upstream, allowing external resolution of internal or reserved domain names. This leaks query information and defeats local policy expectations.
Affected Systems
The vulnerability affects NLnet Labs Unbound versions 1.6.0 through 1.25.1 inclusive. Managing a named view via the unbound-control interface on these releases exposes the issue.
Risk and Exploitability
The CVSS score of 3.1 classifies the risk as low, and the EPSS score is documented as less than 1%. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need either local or privileged access to the unbound-control interface to provoke the problematic view creation. While the likelihood of exploitation is low to moderate, the impact on privacy and policy compliance warrants prompt remediation.
OpenCVE Enrichment