Back to overview

CVE-2026-55708

LOW
3.1
CVSS 3.1
Description
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.

Metadata

CVE ID
CVE-2026-55708
State
PUBLISHED
Assigner
NLnet Labs
Reserved
2026-06-22 12:27 UTC
Published
2026-07-22 13:09 UTC
Last updated
2026-07-22 14:10 UTC
Primary CWE
CWE-1188
CWE-1188: Initialization of a Resource with an Insecure Defa…
Vendor / Product
NLnet Labs / Unbound
Sources
cve.org  ·  NVD

Severity & Metrics

3.1 LOW CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
NLnet Labs Unbound 1.6.0 < 1.25.2
Weakness (CWE)
CWESourceDescription
CWE-1188 cna CWE-1188: Initialization of a Resource with an Insecure Default
CVSS scores (1)
ScoreSeverityVersionSourceVector
3.1 LOW 3.1 cna CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Back to overview