What is CVE-2026-46582?
This vulnerability in NLnet Labs Unbound versions 1.6.0 through 1.25.1 allows a replayed wildcard rrset to be briefly considered DNSSEC-secure and cached before later NSEC validation marks it as bogus. This could temporarily enable DNS cache poisoning attacks. Users are advised to update Unbound to the latest version.
Azərbaycanca: NLnet Labs Unbound 1.6.0-1.25.1 versiyalarında aşkarlanan bu zəiflik, wildcard rrset-in təkrar istifadəsi zamanı DNSSEC yoxlamasının yalnış olaraq keçərli sayılmasına və yaddaşa cache-lənməsinə səbəb olur. Bu, sonrakı NSEC yoxlaması ilə etibarsız hesab edilsə də, müvəqqəti olaraq DNS cache poisoning hücumlarına yol aça bilər. İstifadəçilərə Unbound-u ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
Which versions of the product are affected by CVE-2026-46582?
This vulnerability affects NLnet Labs Unbound versions 1.6.0 through 1.25.1.
How can I protect against CVE-2026-46582?
Users are advised to update NLnet Labs Unbound to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.