What is CVE-2026-44687?
CVE-2026-44687 affects NLnet Labs Unbound from version 1.13.2 up to 1.25.1. An off-by-one error in the 'harden-below-nxdomain' feature allows stub or forward zones with an intermediate label under a DNSSEC-signed zone to be shadowed by a secure NXDOMAIN response from the parent. Users should upgrade to the latest patched version to mitigate this issue.
Azərbaycanca: CVE-2026-44687 NLnet Labs Unbound proqramında aşkarlanıb. Bu zəiflik `harden-below-nxdomain` funksiyasındakı off-by-one xətası səbəbindən, DNSSEC ilə imzalanmış zonada aralıq etiketə malik stub və ya forward zonaların saxta secure NXDOMAIN cavabı ilə kölgələnməsinə yol açır. Təsirə məruz qalmamaq üçün Unbound-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
In which feature of NLnet Labs Unbound was CVE-2026-44687 discovered?
The vulnerability occurs due to an off-by-one error in the 'harden-below-nxdomain' feature.
What is the impact of exploiting CVE-2026-44687?
Stub or forward zones with an intermediate label under a DNSSEC-signed zone can be shadowed by a forged secure NXDOMAIN response from the parent.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.