Executive brief
NLnet Labs Unbound, a widely used tool for translating human-readable website names into computer addresses, contains a vulnerability that allows attackers to keep malicious or decommissioned domains active in the system's memory longer than intended. By exploiting this 'ghost domain' flaw, an attacker who controls a specific domain can force the system to ignore expiration instructions, potentially facilitating phishing or other redirection attacks. This issue affects organizations running their own DNS resolvers and can be resolved by updating to the latest version.
Technical details
Unbound 1.16.2 through 1.25.0 is vulnerable to a 'ghost domain names' attack. An attacker controlling a zone can send a specific Name Server (NS) query that causes Unbound to overwrite expired parent-side referral NS records with child-side apex NS records. This effectively extends the 'ghost domain window' by up to the maximum configured Time-to-Live (TTL) value. While typically requiring a client query, configurations with 'harden-referral-path: yes' are vulnerable to implicit triggers. The vulnerability is remediated in version 1.25.1, which prevents the extension of TTLs for parent NS records regardless of their trust level.
Affected products
- NLnet Labs Unbound 1.16.2 through 1.25.0
Timeline
- 2026-05-20: advisory: Initial disclosure by NLnet Labs
- 2026-05-20: patched: Fixed in Unbound version 1.25.1