CVE-2026-40622Patch(nlnetlabs / unbound)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nlnetlabs unbound systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unbound

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-20); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
unbound

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-05-20: 2Mentions · 2026-07-22: 2Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-07-22: 1Technical Details · 2026-05-20: 1Technical Details · 2026-07-22: 105-2007-22
Signal classification2 categories
Patch
375.0%
General
125.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-202
Patch2
2026-07-222
General1Patch1
Full discourse4 posts
  • Yasuhiro Morishita@OrangeMorishita
    General

    CVE-2026-14586 Medium DoS CVE-2026-32665 High DoS CVE-2026-40691 High DoS CVE-2026-41637 Low DoS CVE-2026-42955 Low CVE-2026-40622(幽霊ドメイン名)の追加修正 CVE-2026-44621 Medium DoS CVE-2026-44687 Low DoS(存在するドメイン名を存在しないと誤認させる) CVE-2026-44690 High キャッシュポイズニング CVE-2026-46582 Low キャッシュポイズニング CVE-2026-50045 Medium 外部へのDoS CVE-2026-50046 Medium DoS CVE-2026-50243 Medium DNSSEC検証のバイパス CVE-2026-50248 Medium DNSSEC Bogusでもゾーン転送の接続先にしてしまう CVE-2026-50251 Medium 外部からの意図的なキャッシュクリアによるDoS CVE-2026-50252 Medium UDPソースポートを外部から推測可能(キャッシュポイズニング) CVE-2026-52863 Medium DoS CVE-2026-54478 Low DNSクッキーの無力化 CVE-2026-55708 Low ローカルな名前を外部に問い合わせてしまう(情報流出) CVE-2026-55717 Medium DoS CVE-2026-55973 High DoS CVE-2026-55990 Medium DoS CVE-2026-55991 Medium DoS CVE-2026-56416 Medium DoS CVE-2026-56444 Medium DoS

    Post summary

    The post lists a series of CVE identifiers with severity tags and brief issue types (mostly DoS and cache poisoning), but offers no deeper technical or actionable details.

    10040503
    4.6K followersView on X
  • strnh@strnh
    Patch

    unbound-1.25.2 来た。 - CVE-2026-42955,CVE-2026-40622: "glue-record を介した 幽霊ドメインの一時的な委任更新" の是正👷 .. 他にも結構あるので、これは上げなければならぬ。

    Post summary

    The tweet announces that Unbound 1.25.2 has been released, providing fixes for CVE‑2026‑42955 and CVE‑2026‑40622, which involve glue‑record temporary delegation updates via phantom domains; no exploits or active exploitation are mentioned.

    02010166
    1.9K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Patch

    ・Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42959, Crash during DNSSEC validation of malicious content. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks to Andrew Griffiths from ‘http://calif.io’ for the report. ・Fix CVE-2026-40622, “Ghost domain name” variant. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-41292, Parsing a long list of incoming EDNS options degrades performance. Thanks to GitHub user ‘N0zoM1z0’, also Qifan Zhang from Palo Alto Networks, for the report. ・Fix CVE-2026-42534, Jostle logic bypass degrades resolution performance. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42923, Degradation of service with unbounded NSEC3 hash calculations. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42960, Possible cache poisoning attack while following delegation. Thanks to TaoFei Guo from Peking University, Yang Luo and JianJun Chen, Tsinghua University, for the report. ・Fix CVE-2026-44390, Unbounded name compression in certain cases causes degradation of service. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

    Post summary

    The passage lists multiple fixed CVEs with brief vulnerability descriptions, signifying the release of patches for these issues.

    11010442
    4.5K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Patch

    "This release consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608."

    Post summary

    The release consolidates multiple security fixes for a set of CVEs, with no mention of PoC, exploit tools, or active exploitation; it focuses purely on patching.

    10000228
    4.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnlnetlabsunbound---

Explore more