Junglewise Threat Intelligence

CVE-2026-12490: NLnet Labs NSD authentication bypass in zone transfers

CVE-2026-12490 · Severity: info · CVSS 8.2 · Published 2026-06-25

Vendors: NLnet Labs.

Executive brief

NLnet Labs NSD, a high-performance DNS name server, contains a security flaw in how it handles zone transfers between servers. An attacker who meets basic network access requirements can bypass mandatory certificate-based authentication to download sensitive DNS zone data. This could lead to the exposure of internal network structures or proprietary DNS records that were intended to be restricted to authorized secondary servers.

Technical details

An improper access control vulnerability (CWE-284) exists in NLnet Labs NSD when 'provide-xfr' is configured with 'tls-auth-name'. While the system is intended to require a specific client certificate for zone transfers, it fails to enforce this requirement if the request is received over the standard TCP port or the regular TLS port (rather than the dedicated 'tls-auth-port'). If 'tls-auth-xfr-only' is not explicitly set to 'yes', an attacker who matches other access control criteria (such as IP address) can bypass the certificate check entirely. This allows unauthorized zone transfers (AXFR/IXFR). The issue is fixed in NSD version 4.14.3.

Affected products

  • NLnet Labs NSD 4.10.1 up to and including 4.14.2

Timeline

  • 2026-06-25: disclosed
  • 2026-06-25: advisory
  • 2026-06-25: patched: Fixed in version 4.14.3

References