Input validation error in Unbound - CVE-2026-50243
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to redirect DNSSEC-protected responses to an operator-configured IP.
The vulnerability exists due to improper input validation in the response-ip/RPZ-IP rewriting handler when processing rewritten upstream A/AAAA answers with invalid DNSSEC signatures. A remote attacker can spoof a BOGUS A/AAAA answer to redirect DNSSEC-protected responses to an operator-configured IP.
Exploitation requires Unbound to be configured with the respip module in front of the validator together with a response-ip redirect rule or an RPZ file with an RPZ-IP trigger.