Insufficient verification of data authenticity in Unbound - CVE-2026-50248
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to replace the entire zone data or the resolver's entire response policy.
The vulnerability exists due to improper validation of configured primary hostnames in auth/rpz zone XFR endpoint selection when resolving a configured primary hostname to BOGUS A/AAAA records. A remote attacker can spoof the hostname's A/AAAA record to replace the entire zone data or the resolver's entire response policy.
No valid RRSIG is required for exploitation.