Back to overview

CVE-2026-50243

MEDIUM
6.3
CVSS 4.0
Description
In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a 'response-ip' redirect rule or an RPZ file with an RPZ-IP trigger, the rewriting handler does not check the security status of the upstream answer and can instead rewrite a BOGUS A/AAAA answer to point to an operator's configured IP. If the validator finds an expired or otherwise invalid RRSIG on an answer whose A record falls within a 'response-ip'/RPZ configuration, the answer is still rewritten and given a hard coded security level of INSECURE. This results in the client receiving an INSECURE NOERROR reply rewritten by the operator's configured IP. A malicious actor can exploit the possible poisonous effect by spoofing a BOGUS A/AAAA answer that falls inside the operator's configured subnet rewrites. Such DNSSEC protected answers are then insecurely redirected to the operator's configured target.

Metadata

CVE ID
CVE-2026-50243
State
PUBLISHED
Assigner
NLnet Labs
Reserved
2026-06-22 12:27 UTC
Published
2026-07-22 13:08 UTC
Last updated
2026-07-22 13:08 UTC
Primary CWE
CWE-348
CWE-348: Use of Less Trusted Source
Vendor / Product
NLnet Labs / Unbound
Sources
cve.org  ·  NVD

Severity & Metrics

6.3 MEDIUM CVSS 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Affected products (1)
VendorProductPlatformVersions
NLnet Labs Unbound 1.6.2 < 1.25.2
Weakness (CWE)
CWESourceDescription
CWE-348 cna CWE-348: Use of Less Trusted Source
CVSS scores (1)
ScoreSeverityVersionSourceVector
6.3 MEDIUM 4.0 cna CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Back to overview