CVE-2026-12490Disclosure(nlnetlabs / nsd)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nlnetlabs nsd systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nsd

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-06-25); latest day: 1
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
nsd

Deep dive

Activity timeline6 mentions / 4d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-26: 1Mentions · 2026-06-29: 2Mentions · 2026-07-06: 1Patch / Workaround · 2026-06-26: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 1Technical Details · 2026-06-29: 106-2506-2606-2907-06
Signal classification3 categories
Disclosure
466.7%
General
116.7%
Patch
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-252
Disclosure1General1
2026-06-261
Patch1
2026-06-292
Disclosure2
2026-07-061
Disclosure1
Full discourse6 posts
  • connect24h@connect24h
    Disclosure

    権威DNSのNSD、今回は後回しにしない方がいい。4件すべてHigh、CVE-2026-12490/12246/12245/12244、修正は4.14.3。DoT 853のDoS、XFRのclient cert bypass、APL/SVCB RR由来のstack/heap破壊まで並ぶのはしんどい。 見どころは「外向きDNS」だけでなくsecondary運用とmulti-tenant DNS。今日見るのはNSD version、provide-xfr/tls-auth-name/tls-auth-xfr-only、DoT公開有無、AXFR/IXFR元、zone転送ログ。DNSは静か守ろう #セキュリティ https://www.security-next.com/186525

    Post summary

    The post announces four high‑severity CVEs in NSD, explains their technical nature, and notes that patch version 4.14.3 is available; no PoC or active exploitation is mentioned.

    0301262.0K
    6.5K followersView on X
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【注意喚起】NSDの脆弱性情報が公開されました(CVE-2026-12244、CVE-2026-12245、CVE-2026-12246、CVE-2026-12490) https://jprs.jp/tech/security/2026-06-29-nsd.html

    Post summary

    The post announces that vulnerability information for four NSD CVEs has been published. No details on exploits, patches, or PoCs are provided.

    031601.4K
    1.3K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    NLnet Labs NSD: 4 "high" CVEs fixed in 4.14.3 https://www.openwall.com/lists/oss-security/2026/06/25/9 CVE-2026-12244: Heap overflow with crafted SVCB RR CVE-2026-12245: Denial of DNS over TLS service CVE-2026-12246: Out of bounds stack write with crafted APL RR CVE-2026-12490: Bypass of client certificate

    Post summary

    NLnet Labs announced that four high-severity CVEs (including a heap overflow, DNS over TLS denial, stack write, and client certificate bypass) have been fixed in NSD 4.14.3.

    01050777
    4.7K followersView on X
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【メールマガジン(FROM JPRS)】最新号を掲載しました。 通常号 vol.1252「NSDの脆弱性情報が公開されました(CVE-2026-12244、CVE-2026-12245、CVE-2026-12246、CVE-2026-12490)、他2件」など https://jprs.jp/mail/backnumber/2026/260706.html

    Post summary

    The newsletter announces the publication of vulnerability information for several CVE‑2026‑12xxx identifiers, providing only the CVE numbers without further technical or exploitation details.

    00031367
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    (続き) CVE-2026-12246:APLレコードの実装不具合でセカンダリサーバーのゾーンデータを破壊可能。 CVE-2026-12490:XFR over TLS(XoT)の実装不具合でクライアント証明書による認証がバイパスされる。

    Post summary

    The post announces two DNS‑related CVEs: CVE‑2026‑12246 (APL record bug that can destroy secondary server zone data) and CVE‑2026‑12490 (XFR‑over‑TLS flaw that bypasses client‑certificate authentication).

    10020189
    4.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-12490 Missing Client Certificate Validation in Zone Transfer Authentication https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-12490

    Post summary

    The text gives a simple CVE entry with a brief technical description and a link to a vulnerability detail page, but does not mention PoC, exploit, or patch information.

    00000111
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnlnetlabsnsd---

Explore more