CVE-2026-50248: BOGUS configured primary hostname accepted for XFR in auth/rpz zones
BOGUS configured primary hostname accepted for XFR in auth/rpz zones
Other sources
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.25.2-1 - Upgrade
Upgrade
NLnet Labs Unboundto a version that resolves this vulnerability.Fixed in 1.25.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50248?
The severity of CVE-2026-50248 is medium, rated at 6.5 on the CVSS scale.
How do I fix CVE-2026-50248?
To address CVE-2026-50248, update to a version of Unbound beyond 1.25.1 that resolves the vulnerability.
What are the potential impacts of CVE-2026-50248?
CVE-2026-50248 may allow a malicious actor to spoof and exploit vulnerabilities due to improperly configured primary hostnames in auth/rpz zones.
Which software versions are affected by CVE-2026-50248?
CVE-2026-50248 affects NLnet Labs Unbound versions from 1.7.0 up to and including 1.25.1.
What types of attacks could exploit CVE-2026-50248?
Exploitation of CVE-2026-50248 could lead to unauthorized access through XFR opportunities in the context of DNS services.