Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.7
CVE-2026-42960: Unbound DNS resolver can be tricked into cache poisoning
CVE-2026-42960 · published 4 months ago
Summary
Versions of the Unbound DNS service up to 1.25.0 may store false DNS information if an attacker sends specially crafted responses. This could cause users to be directed to malicious sites or intercept communications. Upgrade to version 1.25.1 or later, which blocks the unwanted data, to protect against this risk.
What to do
- Update canonical unbound to version 1.22.0-2ubuntu2.3.
- Update canonical unbound to version 1.24.2-1ubuntu2.1.
- Update debian rootio-unbound to version 1.13.1-1+deb11u7.aikido.1.
- Update debian unbound to version 1.25.1-1.
- Update canonical unbound to version 1.4.22-1ubuntu4.14.04.3+esm3.
- Update canonical unbound to version 1.5.8-1ubuntu1.1+esm3.
- Update canonical unbound to version 1.6.7-1ubuntu2.6+esm4.
- Update canonical unbound to version 1.9.4-2ubuntu1.11+esm1.
- Update canonical unbound to version 1.13.1-1ubuntu5.15.
- Update canonical unbound to version 1.19.2-1ubuntu3.8.
- Update debian rootio-unbound to version 1.17.1-2+deb12u3.root.io.1.
- Update debian unbound to version 1.17.1-2+deb12u4.aikido.2.
- Update debian rootio-unbound to version 1.17.1-2+deb12u4.aikido.2.
- Update debian unbound to version 1.13.1-1+deb11u7.aikido.1.
- Update debian rootio-unbound to version 1.13.1-1+deb11u7.aikido.6.
- Update debian unbound to version 1.13.1-1+deb11u7.aikido.3.
- Update debian rootio-unbound to version 1.13.1-1+deb11u7.aikido.3.
- Update debian unbound to version 1.13.1-1+deb11u7.aikido.6.
- Update debian unbound to version 1.17.1-2+deb12u4.aikido.3.
- Update debian rootio-unbound to version 1.17.1-2+deb12u4.aikido.3.
- Update debian unbound to version 1.17.1-2+deb12u4.aikido.4.
- Update debian rootio-unbound to version 1.17.1-2+deb12u4.aikido.4.
- Update unbound to version 1.17.1-2+deb12u4.aikido.5.
- Update rootio-unbound to version 1.17.1-2+deb12u4.aikido.5.
- Update unbound to version 1.25.2-r0.
- Update unbound to version 1.25.1-r0.
- Update nlnetlabs unbound to version 1.25.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Ubuntu:25.10 | canonical | unbound |
< 1.22.0-2ubuntu2.3 Fix: upgrade to 1.22.0-2ubuntu2.3
|
| Ubuntu:26.04:LTS | canonical | unbound |
< 1.24.2-1ubuntu2.1 Fix: upgrade to 1.24.2-1ubuntu2.1
|
| Root:Debian:11 | debian | rootio-unbound |
< 1.13.1-1+deb11u7.aikido.1 < 1.13.1-1+deb11u7.aikido.6 < 1.13.1-1+deb11u7.aikido.3 Fix: upgrade to 1.13.1-1+deb11u7.aikido.1
|
| – | nlnetlabs | unbound |
< 1.25.1 cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:* |
| Debian:11 | debian | unbound | All versions |
| Debian:12 | debian | unbound | All versions |
| Debian:13 | debian | unbound | All versions |
| Debian:14 | debian | unbound |
< 1.25.1-1 Fix: upgrade to 1.25.1-1
|
| Ubuntu:Pro:14.04:LTS | canonical | unbound |
< 1.4.22-1ubuntu4.14.04.3+esm3 Fix: upgrade to 1.4.22-1ubuntu4.14.04.3+esm3
|
| Ubuntu:Pro:16.04:LTS | canonical | unbound |
< 1.5.8-1ubuntu1.1+esm3 Fix: upgrade to 1.5.8-1ubuntu1.1+esm3
|
| Ubuntu:Pro:18.04:LTS | canonical | unbound |
< 1.6.7-1ubuntu2.6+esm4 Fix: upgrade to 1.6.7-1ubuntu2.6+esm4
|
| Ubuntu:Pro:20.04:LTS | canonical | unbound |
< 1.9.4-2ubuntu1.11+esm1 Fix: upgrade to 1.9.4-2ubuntu1.11+esm1
|
| Ubuntu:22.04:LTS | canonical | unbound |
< 1.13.1-1ubuntu5.15 Fix: upgrade to 1.13.1-1ubuntu5.15
|
| Ubuntu:24.04:LTS | canonical | unbound |
< 1.19.2-1ubuntu3.8 Fix: upgrade to 1.19.2-1ubuntu3.8
|
| Root:Debian:12 | debian | rootio-unbound |
< 1.17.1-2+deb12u3.root.io.1 < 1.17.1-2+deb12u4.aikido.2 < 1.17.1-2+deb12u4.aikido.3 < 1.17.1-2+deb12u4.aikido.4 Fix: upgrade to 1.17.1-2+deb12u3.root.io.1
|
| Root:Debian:12 | debian | unbound |
< 1.17.1-2+deb12u4.aikido.2 < 1.17.1-2+deb12u4.aikido.3 < 1.17.1-2+deb12u4.aikido.4 Fix: upgrade to 1.17.1-2+deb12u4.aikido.2
|
| Root:Debian:11 | debian | unbound |
< 1.13.1-1+deb11u7.aikido.1 < 1.13.1-1+deb11u7.aikido.3 < 1.13.1-1+deb11u7.aikido.6 Fix: upgrade to 1.13.1-1+deb11u7.aikido.1
|
| Root:Debian:12 | – | unbound |
< 1.17.1-2+deb12u4.aikido.5 Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
|
| Root:Debian:12 | – | rootio-unbound |
< 1.17.1-2+deb12u4.aikido.5 Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
|
| Alpine:v3.22 | – | unbound |
< 1.25.2-r0 Fix: upgrade to 1.25.2-r0
|
| Alpine:v3.24 | – | unbound |
< 1.25.1-r0 Fix: upgrade to 1.25.1-r0
|
Original advisory text
CVE-2026-42960 in unbound - Patched by Root
NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.
References
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42960.txt
- https://security-tracker.debian.org/tracker/CVE-2026-42960 Vendor Advisory
- https://ubuntu.com/security/notices/USN-8282-1 Vendor Advisory
- https://nlnetlabs.nl/news/2026/May/20/unbound-1.25.1-released/ Third Party Advisory
- https://ubuntu.com/security/CVE-2026-42960 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-42960 Third Party Advisory
- https://ubuntu.com/security/notices/USN-8282-2 Vendor Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-42960 Vendor Advisory
Severity
5.7
Medium
CVSS 4.0: 5.7 (NVD)
CVSS 4.0: 7.8 (OSV)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-349Acceptance of Extraneous Untrusted Data With Trusted Data
Timeline
Published20 May 2026
Updated25 Sep 2026
First seen20 May 2026
Sources
CVE-2026-42960 · NVD
DEBIAN-CVE-2026-42960 · OSV
UBUNTU-CVE-2026-42960 · OSV
CVE-2026-42960 · OSV
ALPINE-CVE-2026-42960 · OSV
Track software like this
Free during beta