CVE Vulnerabilities

CVE-2026-50248

Insufficient Verification of Data Authenticity

Published: Jul 22, 2026 | Modified: Jul 22, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostnames A/AAAA record (no valid RRSIG required) becomes the zones XFR primary and can replaces the entire zone/the resolvers entire response policy.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

NameVendorStart VersionEnd Version
UnboundUbuntuupstream*

References