Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.5

CVE-2026-50248: Unbound DNS resolver allows unauthorized zone takeover

CVE-2026-50248
Summary

A vulnerability in Unbound's DNS resolver allows a malicious actor to take control of a DNS zone by spoofing its hostname's IP address. This can lead to unauthorized changes to the zone's settings and potentially disrupt internet access for users relying on the affected DNS resolver. To mitigate this issue, update to a version of Unbound that fixes this vulnerability.

Original title
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A m...
Original description
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.
nvd CVSS3.1 6.5
Vulnerability type
CWE-345
Published: 22 Jul 2026 · Updated: 22 Jul 2026 · First seen: 22 Jul 2026