CVE-2026-55708
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
- Puntuación base: 3.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 5
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-1188
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-55708",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-55708",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-07-22T14:09:14.145226Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "sep@nlnetlabs.nl",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.1,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 0.6
}
]
},
"affected": [
{
"source": "sep@nlnetlabs.nl",
"affectedData": [
{
"vendor": "NLnet Labs",
"product": "Unbound",
"versions": [
{
"status": "affected",
"version": "1.6.0",
"lessThan": "1.25.2",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-07-22T14:17:21.403",
"references": [
{
"url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-55708.txt",
"tags": [
"Vendor Advisory"
],
"source": "sep@nlnetlabs.nl"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "sep@nlnetlabs.nl",
"description": [
{
"lang": "en",
"value": "CWE-1188"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations."
}
],
"lastModified": "2026-07-24T14:24:10.027",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "08138649-8C21-4AD6-ADC3-45CD66607B71",
"versionEndExcluding": "1.25.2",
"versionStartIncluding": "1.6.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "sep@nlnetlabs.nl"
}