CVE-2026-77955
published 2026-09-16CVE-2026-77955: In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a…
PriorityP424medium4.4CVSS 3.1
AVNACHPRHUINSUCNIHAN
EPSS
0.13%
2.8th percentile
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.13.2 < 1.26.1 | 1.26.1 |
| openshift | ose-rhel-coreos-8 | — | — |
| openshift | ose-rhel-coreos-9 | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window w
ghsa_unreviewed·2026-09-16
CVE-2026-77955 [MEDIUM] CWE-345 In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window w
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.
Red Hat
unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution
vendor_redhat·2026-09-16·CVSS 4.4
CVE-2026-77955 [MEDIUM] CWE-367 unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution
unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution
A flaw was found in Unbound. This vulnerability affects ZONEMD configured zones that are located below a trust anchor, allowing tampered zone contents to be served or stored to disk before integrity checks are completed. This occurs due to the asynchronous resolution of DS/DNSKEY records, which creates a window where the integrity check is not yet finalized. Consequently, if a zone file is written to disk while the ZONEMD check has not yet completed or failed, the compromised data can be reloaded on startup and remain available until ZONEMD verification concludes again, potentially leading to the serving of incorrect DNS information.
Package: openshift/ose-rhel-coreos-8 (Red Hat OpenShift Container Platfor
No detection rules found.
No public exploits indexed.
Hackernews
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
blogs_hackernews·2026-09-17·CVSS 9.8
CVE-2026-81642 [CRITICAL] Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws. One of the eight, CVE-2026-82717 , is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code
Bugzilla
CVE-2026-77955 unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution [fedora-all]
bugzilla·2026-09-21·CVSS 4.4
CVE-2026-77955 [MEDIUM] CVE-2026-77955 unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution [fedora-all]
CVE-2026-77955 unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefil
Bugzilla
CVE-2026-77955 unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution
bugzilla·2026-09-16·CVSS 4.4
CVE-2026-77955 [MEDIUM] CVE-2026-77955 unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution
CVE-2026-77955 unbound: Unbound: ZONEMD verification bypass due to asynchronous DNSSEC resolution
In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future relo
2026-09-16
Published