What is CVE-2026-55708?
CVE-2026-55708 is a vulnerability in NLnet Labs Unbound versions 1.6.0 through 1.25.1, where the 'view_local_data' and 'view_local_datas' commands in 'unbound-control' create a bare local zones tree for a configured named view with no initial local data. This flaw can be exploited by unauthorized users, and updating to the latest version is recommended for affected systems.
Azərbaycanca: CVE-2026-55708, NLnet Labs Unbound 1.6.0-dan 1.25.1-ə qədər versiyalarda 'unbound-control' əmrinin 'view_local_data' və 'view_local_datas' funksiyalarında zəiflikdir. Bu, konfiqurasiya zamanı lokal məlumatı olmayan 'view' üçün boş lokal zona ağacı yaradılmasına səbəb olur ki, təsdiqlənməmiş istifadəçilər tərəfindən istismar oluna bilər. Təsirə məruz qalan sistemlərdə proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which functions in the 'unbound-control' command are affected by CVE-2026-55708?
The vulnerability CVE-2026-55708 affects the 'view_local_data' and 'view_local_datas' functions of the 'unbound-control' command.
What measure is recommended to mitigate CVE-2026-55708?
To mitigate CVE-2026-55708, it is recommended to update NLnet Labs Unbound to the latest version on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.