Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 16

Количество 16

ubuntu логотип

CVE-2026-40622

2 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-40622

2 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-40622

2 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-40622

2 месяца назад

Another 'ghost domain names' attack variant

EPSS: Низкий
debian логотип

CVE-2026-40622

2 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vul ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20260713-73-0011

19 дней назад

Уязвимость unbound

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-m3vq-fgh9-hq65

2 месяца назад

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:37282

3 дня назад

Important: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:36777

3 дня назад

Important: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:36320

3 дня назад

Important: unbound security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-37282

23 дня назад

ELSA-2026-37282: unbound security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36777

23 дня назад

ELSA-2026-36777: unbound security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-36320

16 дней назад

ELSA-2026-36320: unbound security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21083-1

около 1 месяца назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2369-1

около 2 месяцев назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:2281-1

около 2 месяцев назад

Security update for unbound

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-40622

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-40622

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-40622

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-40622

Another 'ghost domain names' attack variant

0%
Низкий
2 месяца назад
debian логотип
CVE-2026-40622

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vul ...

CVSS3: 7.5
0%
Низкий
2 месяца назад
redos логотип
ROS-20260713-73-0011

Уязвимость unbound

CVSS3: 7.5
0%
Низкий
19 дней назад
github логотип
GHSA-m3vq-fgh9-hq65

NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.

CVSS3: 7.5
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:37282

Important: unbound security update

3 дня назад
rocky логотип
RLSA-2026:36777

Important: unbound security update

3 дня назад
rocky логотип
RLSA-2026:36320

Important: unbound security update

3 дня назад
oracle-oval логотип
ELSA-2026-37282

ELSA-2026-37282: unbound security update (IMPORTANT)

23 дня назад
oracle-oval логотип
ELSA-2026-36777

ELSA-2026-36777: unbound security update (IMPORTANT)

23 дня назад
oracle-oval логотип
ELSA-2026-36320

ELSA-2026-36320: unbound security update (IMPORTANT)

16 дней назад
suse-cvrf логотип
openSUSE-SU-2026:21083-1

Security update for unbound

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:2369-1

Security update for unbound

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2026:2281-1

Security update for unbound

около 2 месяцев назад

Уязвимостей на страницу