Possible ZONEMD verification bypass window
Summary
| CVE | CVE-2026-77955 |
|---|---|
| State | PUBLISHED |
| Assigner | NLnet Labs |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-16 09:17:05 UTC |
| Updated | 2026-09-23 20:19:28 UTC |
| Description | In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads. |
Risk And Classification
Primary CVSS: v3.1 4.4 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS: 0.001500000 probability, percentile 0.034780000 (date 2026-09-24)
Problem Types: CWE-345 | CWE-345 CWE-345: Insufficient Verification of Data Authenticity
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.4 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N |
| 3.1 | CNA | CVSS | 4.4 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
HighUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | NLnet Labs | Unbound | affected 1.13.2 1.26.1 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.nlnetlabs.nl/downloads/unbound/CVE-2026-77955.txt | [email protected] | www.nlnetlabs.nl | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Yuqi Qiu (Nankai University, AOSP Lab) (en)
CNA: Xiang Li (Nankai University, AOSP Lab) (en)
CNA: Qifan Zhang (Palo Alto Networks) (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2026-08-11T00:00:00.000Z | Issue reported by Yuqi Qiu |
| CNA | 2026-08-16T00:00:00.000Z | Issue reported by Qifan Zhang |
| CNA | 2026-08-19T00:00:00.000Z | NLnet Labs shares patch with Yuqi Qiu |
| CNA | 2026-08-20T00:00:00.000Z | Yuqi Qiu verifies patch |
| CNA | 2026-09-01T00:00:00.000Z | NLnet Labs shares patch with Qifan Zhang |
| CNA | 2026-09-16T00:00:00.000Z | Fixes released with version 1.26.1 |
Solutions
CNA: This issue is fixed starting with version 1.26.1
There are currently no legacy QID mappings associated with this CVE.