CVE-2026-42960Patch(nlnetlabs / unbound)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nlnetlabs unbound systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-349

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unbound

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 3 signals
  • Peaked 2d ago at 2 mentions (2026-05-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
unbound

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-05-20: 2Mentions · 2026-05-21: 1Mentions · 2026-05-26: 1Patch / Workaround · 2026-05-20: 2Patch / Workaround · 2026-05-21: 1Patch / Workaround · 2026-05-26: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-26: 105-2005-2105-26
Signal classification1 categories
Patch
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-202
Patch2
2026-05-211
Patch1
2026-05-261
Patch1
Full discourse4 posts
  • Yasuhiro Morishita@OrangeMorishita
    Patch

    ・Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42959, Crash during DNSSEC validation of malicious content. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks to Andrew Griffiths from ‘http://calif.io’ for the report. ・Fix CVE-2026-40622, “Ghost domain name” variant. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-41292, Parsing a long list of incoming EDNS options degrades performance. Thanks to GitHub user ‘N0zoM1z0’, also Qifan Zhang from Palo Alto Networks, for the report. ・Fix CVE-2026-42534, Jostle logic bypass degrades resolution performance. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42923, Degradation of service with unbounded NSEC3 hash calculations. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42960, Possible cache poisoning attack while following delegation. Thanks to TaoFei Guo from Peking University, Yang Luo and JianJun Chen, Tsinghua University, for the report. ・Fix CVE-2026-44390, Unbounded name compression in certain cases causes degradation of service. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

    Post summary

    The notice announces that a series of DNS-related CVEs have been fixed, providing brief technical details for each vulnerability.

    11010442
    4.5K followersView on X
  • MY TECH BLOG@MyTechBlogJP
    Patch

    Unbound の CVE-2026-42960 が公開(CVSS 10.0) 1.25.0 以下が対象で、修正版 1.25.1 への移行が推奨 ・MX 等の非 NS RRSet 経由のキャッシュポイズン ・NVD と CNA で CVSS 評価が大きく異なる背景も解説 ・移行手順とキャッシュフラッシュまで網羅 https://mytech-blog.com/unbound-cve-2026-42960/ #Unbound

    Post summary

    The post announces CVE‑2026‑42960 in Unbound, explains a cache‑poisoning flaw, and recommends upgrading to version 1.25.1, but no PoC, exploit code, or active exploitation claims are presented.

    01000177
    174 followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Patch

    "This release consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608."

    Post summary

    The release announces that security patches for a suite of CVE‑2026 vulnerabilities are included, confirming that remediation is available.

    10000228
    4.5K followersView on X
  • ThreatAft@ThreatAft
    Patch

    🔐 NLnet Labs released Unbound 1.25.1 with fixes for 11 CVEs — including a use-after-free in the DNSSEC validator (CVE-2026-33278) that could lead to remote code execution, and a cache poisoning flaw (CVE-2026-42960). 🔗 https://threataft.com/articles/unbound-1-25-1-11-cves-dnssec-rce-cache-poisoning #CyberSecurity #ThreatIntel #DNS

    Post summary

    NLnet Labs announced the Unbound 1.25.1 release that patches 11 CVEs, notably a use‑after‑free vulnerability capable of remote code execution and a cache poisoning flaw.

    0000093
    26 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnlnetlabsunbound---

Explore more