CVE-2026-50248
published 2026-07-22CVE-2026-50248: In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still…
PriorityP337medium6.5CVSS 3.1
AVNACHPRNUINSUCNIHAL
EPSS
0.17%
5.4th percentile
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.7.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
| nlnetlabs | unbound | >= 1.7.0 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
unbound: Unbound: DNS response policy replacement via hostname spoofing
vendor_redhat·2026-07-22·CVSS 6.5
CVE-2026-50248 [MEDIUM] CWE-345 unbound: Unbound: DNS response policy replacement via hostname spoofing
unbound: Unbound: DNS response policy replacement via hostname spoofing
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.
A flaw in Unbound allows a remote attacker to replace an authenticated or Response Policy Zone (RPZ) by spoofing DNS records for configured primary hostnames. This enables the attacker to impersonate the primary server, leading to DNS cache poisoning or traffic redirection.
Statement: A Moderate impact flaw in Unbound allows a remote atta
GHSA
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint.
ghsa_unreviewed·2026-07-22
CVE-2026-50248 [MEDIUM] CWE-345 In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint.
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.
No detection rules found.
No public exploits indexed.
2026-07-22
Published