What is CVE-2026-44690?
This flaw affects NLnet Labs Unbound versions 1.7.0 through 1.25.1. Insufficient validation of the RRSIG.Labels field combined with premature cache writes during RFC 8198 aggressive NSEC processing enables cache poisoning. A malicious actor controlling a single delegated zone can poison arbitrary subdomains, so applying the security patch is essential.
Azərbaycanca: Bu boşluq NLnet Labs Unbound (1.7.0–1.25.1) proqramında aşkarlanıb. RRSIG.Labels sahəsinin kifayət qədər yoxlanılmaması və RFC 8198 aqressiv NSEC emalı zamanı vaxtından əvvəl keşə yazma əməliyyatı keş zəhərlənməsinə səbəb olur. Təcavüzkar tək bir idarə olunan zonadan istifadə edərək ixtiyari alt domenləri zəhərləyə bilər, ona görə də təhlükəsizlik yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
Which software is affected by CVE-2026-44690?
This flaw affects NLnet Labs Unbound versions 1.7.0 through 1.25.1.
What can an attacker achieve by exploiting CVE-2026-44690?
A malicious actor controlling a single delegated zone can poison arbitrary subdomains through cache poisoning that occurs during RFC 8198 aggressive NSEC processing.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.