CVE-2026-42960CRITICAL 10.0EPSS p16.0%

CVE-2026-42960CVE-2026-42960

Description

NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority section. Promiscuous RRSets that complement DNS replies in the authority section can be used to trick Unbound to cache such records. If an adversary is able to attach such records in a reply (i.e., spoofed packet, fragmentation attack) he would be able to poison Unbound's cache. A malicious actor can exploit the possible poisonous effect by injecting RRSets other than NS that are also accompanied by address records in a reply, for example MX. This could be achieved by trying to spoof a reply packet or fragmentation attacks. Unbound would then accept the relative address records in the additional section and cache them if the authority RRSet has enough trust at this point, i.e., in-zone data for the delegation point. Unbound 1.25.1 contains a patch with a fix that disregards address records from the additional section if they are not explicitly relevant only to authority NS records, mitigating the possible poison effect. This is a complement fix to CVE-2025-11411.

Scoring

CVSS 3.110.0 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
EPSS0.25% probability of exploitation · percentile 16.0% · 2026-06-18T12:00:27Z
Published2026-05-20
Last modified2026-05-20

Underlying weaknesses· 1

CWE-349

References

  1. https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42960.txt

1

TypeTargetConfidenceTier
WeaknessAcceptance of Extraneous Untrusted Data With Trusted Datacwe-3490%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-40778
CVE
CVE-2026-33278
CVE
CVE-2026-10846
CVE
CVE-2025-40776
CVE
CVE-2026-3593
CVE
CVE-2025-59023
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.