Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 15

Количество 15

ubuntu логотип

CVE-2026-44690

2 месяца назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-44690

2 месяца назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2026-44690

2 месяца назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 7.5
EPSS: Низкий
msrc логотип

CVE-2026-44690

2 месяца назад

Cross-zone wildcard cache poisoning via RRSIG.labels manipulation

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-44690

2 месяца назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient v ...

CVSS3: 7.5
EPSS: Низкий
rocky логотип

RLSA-2026:55784

около 1 месяца назад

Important: unbound security update

EPSS: Низкий
github логотип

GHSA-jwg4-375h-655h

2 месяца назад

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2026-55784

около 1 месяца назад

ELSA-2026-55784: unbound security update (IMPORTANT)

EPSS: Низкий
rocky логотип

RLSA-2026:55892

около 1 месяца назад

Important: unbound security update

EPSS: Низкий
rocky логотип

RLSA-2026:55841

около 1 месяца назад

Important: unbound security update

EPSS: Низкий
oracle-oval логотип

ELSA-2026-55892

около 1 месяца назад

ELSA-2026-55892: unbound security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2026-55841

около 1 месяца назад

ELSA-2026-55841: unbound security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3884-1

22 дня назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:3885-1

22 дня назад

Security update for unbound

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:21550-1

около 1 месяца назад

Security update for unbound

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-44690

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 7.5
0%
Низкий
2 месяца назад
redhat логотип
CVE-2026-44690

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 8.6
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-44690

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 7.5
0%
Низкий
2 месяца назад
msrc логотип
CVE-2026-44690

Cross-zone wildcard cache poisoning via RRSIG.labels manipulation

CVSS3: 7.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2026-44690

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient v ...

CVSS3: 7.5
0%
Низкий
2 месяца назад
rocky логотип
RLSA-2026:55784

Important: unbound security update

0%
Низкий
около 1 месяца назад
github логотип
GHSA-jwg4-375h-655h

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing leads to cache poisoning that permits a malicious actor controlling a single delegated zone to poison arbitrary sibling zones under NSEC-signed parent domains. A malicious actor with one registered domain under an NSEC-signed TLD can serve malicious insecure DNS responses for unrelated sibling domains (sharing the same parent zone). Arbitrary delegations that do not exist under the parent domain and are covered by the parent's NSEC chain can be brought into insecure existence by fraudulent wildcard DS records (less labels than expected, unknown algorithm) from the malicious sibling domain. This allows the malicious actor to inject insecure wildcard records for those delegations.

CVSS3: 7.5
0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2026-55784

ELSA-2026-55784: unbound security update (IMPORTANT)

0%
Низкий
около 1 месяца назад
rocky логотип
RLSA-2026:55892

Important: unbound security update

около 1 месяца назад
rocky логотип
RLSA-2026:55841

Important: unbound security update

около 1 месяца назад
oracle-oval логотип
ELSA-2026-55892

ELSA-2026-55892: unbound security update (IMPORTANT)

около 1 месяца назад
oracle-oval логотип
ELSA-2026-55841

ELSA-2026-55841: unbound security update (IMPORTANT)

около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:3884-1

Security update for unbound

22 дня назад
suse-cvrf логотип
SUSE-SU-2026:3885-1

Security update for unbound

22 дня назад
suse-cvrf логотип
openSUSE-SU-2026:21550-1

Security update for unbound

около 1 месяца назад

Уязвимостей на страницу