What is CVE-2026-50248?
CVE-2026-50248 affects NLnet Labs Unbound versions 1.7.0 to 1.25.1, where a configured auth/RPZ zone accepts a BOGUS primary hostname as a valid XFR endpoint. Upgrading to the latest version is urgently recommended.
Azərbaycanca: CVE-2026-50248, NLnet Labs Unbound-un 1.7.0-dən 1.25.1-ə qədər versiyalarında aşkarlanıb. Auth/RPZ zonada 'primary hostname' BOGUS olarsa belə, XFR endpoint kimi qəbul edilir. Təcili olaraq Unbound-u son versiyaya yeniləyin.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ1
What is the exact flaw in NLnet Labs Unbound described by CVE-2026-50248?
The flaw involves an auth/RPZ zone configuration accepting a BOGUS primary hostname as a valid XFR endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.