CVE-2026-50243: 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
Other sources
In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of the upstream answer and can instead rewrite a BOGUS A/AAAA answer to point to an operator's configured IP. If the validator finds an expired or otherwise invalid RRSIG on an answer whose A record falls within a 'response-ip'/RPZ configuration, the answer is still rewritten and given a hard coded security level of INSECURE. This results in the client receiving an INSECURE NOERROR reply rewritten by the operator's configured IP. A malicious actor can exploit the possible poisonous effect by spoofing a BOGUS A/AAAA answer that falls inside the operator's configured subnet rewrites. Such DNSSEC protected answers are then insecurely redirected to the operator's configured target.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.25.2-1 - Upgrade
Upgrade
NLnet Labs Unboundto a version that resolves this vulnerability.Fixed in 1.25.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50243?
CVE-2026-50243 has a medium severity rating of 6.3 based on its CVSS score.
What does CVE-2026-50243 affect?
CVE-2026-50243 affects NLnet Labs Unbound versions 1.6.2 through 1.25.1.
How can CVE-2026-50243 be mitigated?
To mitigate CVE-2026-50243, it's recommended to update NLnet Labs Unbound to a newer version that resolves this vulnerability.
What is the nature of the vulnerability in CVE-2026-50243?
CVE-2026-50243 allows the 'response-ip' and RPZ features to rewrite BOGUS DNS answers instead of returning a SERVFAIL response.
When was CVE-2026-50243 published?
CVE-2026-50243 was published on July 22, 2026.