Executive brief
NLnet Labs Unbound, a widely used DNS resolver, contains a flaw in how it handles specific security rules for redirecting web traffic. Under certain configurations, the software may fail to verify the authenticity of a security-protected DNS response, allowing it to be redirected to an operator-defined IP address even if the response is invalid or forged. This could allow a remote attacker to bypass DNSSEC security protections and potentially misdirect users to unintended network locations.
Technical details
A vulnerability exists in Unbound's 'respip' module when positioned before the validator in the module stack. When configured with 'response-ip' redirect rules or RPZ-IP triggers, the rewriting handler fails to validate the security status of upstream A/AAAA records. If an attacker spoofs a BOGUS answer (e.g., one with an expired RRSIG) that matches a configured subnet rewrite, Unbound will rewrite the answer to the operator's target IP and downgrade the security status to INSECURE rather than rejecting it. This allows DNSSEC-protected records to be insecurely redirected. The issue is fixed in Unbound version 1.25.2.
Affected products
- NLnet Labs Unbound 1.6.2 up to and including 1.25.1
Timeline
- 2026-07-22: advisory
- 2026-07-22: patched: Fixed in version 1.25.2