Junglewise Threat Intelligence

CVE-2026-50243: NLnet Labs Unbound DNSSEC validation bypass in respip module

CVE-2026-50243 · Severity: info · CVSS 6.3 · Published 2026-07-22

Technologies: NLnet Labs Unbound. Vendors: NLnet Labs.

Executive brief

NLnet Labs Unbound, a widely used DNS resolver, contains a flaw in how it handles specific security rules for redirecting web traffic. Under certain configurations, the software may fail to verify the authenticity of a security-protected DNS response, allowing it to be redirected to an operator-defined IP address even if the response is invalid or forged. This could allow a remote attacker to bypass DNSSEC security protections and potentially misdirect users to unintended network locations.

Technical details

A vulnerability exists in Unbound's 'respip' module when positioned before the validator in the module stack. When configured with 'response-ip' redirect rules or RPZ-IP triggers, the rewriting handler fails to validate the security status of upstream A/AAAA records. If an attacker spoofs a BOGUS answer (e.g., one with an expired RRSIG) that matches a configured subnet rewrite, Unbound will rewrite the answer to the operator's target IP and downgrade the security status to INSECURE rather than rejecting it. This allows DNSSEC-protected records to be insecurely redirected. The issue is fixed in Unbound version 1.25.2.

Affected products

  • NLnet Labs Unbound 1.6.2 up to and including 1.25.1

Timeline

  • 2026-07-22: advisory
  • 2026-07-22: patched: Fixed in version 1.25.2

References

Related threats