CVE-2026-42955
published 2026-07-22CVE-2026-42955: In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found…
PriorityP416low3.7CVSS 3.1
AVNACHPRNUINSUCNILAN
EPSS
0.20%
9.5th percentile
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnetlabs | unbound | — | — |
| nlnetlabs | unbound | >= 1.16.2 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
unbound: Unbound: DNS cache integrity issue
vendor_redhat·2026-07-22·CVSS 3.7
CVE-2026-42955 [LOW] CWE-354 unbound: Unbound: DNS cache integrity issue
unbound: Unbound: DNS cache integrity issue
A "ghost domain names" flaw in Unbound allows a remote attacker controlling a domain to manipulate cached DNS records. By extending the lifetime of outdated DNS information, an attacker can cause clients to receive stale or misleading DNS responses.
Statement: This Low impact DNS cache integrity issue in Unbound allows an attacker to extend the window for serving outdated DNS information. Exploitation requires an adversary to control a ghost zone and query a vulnerable Unbound instance. The risk is elevated if the non-default `harden-referral-path: yes` configuration is enabled, as it removes the need for a client query.
Mitigation: To mitigate this issue, ensure harden-referral-path is set to no (the default) to prevent Unbound from implicitl
GHSA
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost d
ghsa_unreviewed·2026-07-22·CVSS 7.5
CVE-2026-42955 [HIGH] CWE-672 In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost d
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a vari
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42955 unbound: Unbound: DNS cache integrity issue [fedora-all]
bugzilla·2026-07-28·CVSS 7.5
CVE-2026-42955 [HIGH] CVE-2026-42955 unbound: Unbound: DNS cache integrity issue [fedora-all]
CVE-2026-42955 unbound: Unbound: DNS cache integrity issue [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-si
Bugzilla
CVE-2026-42955 unbound: Unbound: DNS cache integrity issue
bugzilla·2026-07-22·CVSS 7.5
CVE-2026-42955 [HIGH] CVE-2026-42955 unbound: Unbound: DNS cache integrity issue
CVE-2026-42955 unbound: Unbound: DNS cache integrity issue
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required
2026-07-22
Published