What is CVE-2026-50243?
In NLnet Labs Unbound versions 1.6.2 up to 1.25.1, when the `respip` module is used before the validator with a `response-ip` redirect rule or RPZ-IP trigger, the rewriting handler fails to check the security status of the upstream answer. This could lead to accepting unvalidated responses. Upgrading to the latest Unbound version is recommended.
Azərbaycanca: NLnet Labs Unbound 1.6.2-dən 1.25.1-ə qədər olan versiyalarda, `respip` modulu validator qarşısında `response-ip` yönləndirmə qaydası və ya RPZ-IP trigger istifadə edildikdə, yenidən yazma emalı yuxarı cavabın təhlükəsizlik statusunu yoxlamır. Bu, təsdiqlənməmiş cavabların qəbuluna səbəb ola bilər. Unbound-u ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
Which versions of Unbound are affected by CVE-2026-50243?
This vulnerability affects NLnet Labs Unbound versions 1.6.2 up to 1.25.1.
What should I do to protect against CVE-2026-50243?
Upgrading to the latest Unbound version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.