{"api_version":"1","generated_at":"2026-10-01T20:32:28+00:00","cve":"CVE-2026-77955","urls":{"html":"https://cve.report/CVE-2026-77955","api":"https://cve.report/api/cve/CVE-2026-77955.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-77955","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-77955"},"summary":{"title":"Possible ZONEMD verification bypass window","description":"In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.","state":"PUBLISHED","assigner":"NLnet Labs","published_at":"2026-09-16 09:17:05","updated_at":"2026-09-23 20:19:28"},"problem_types":["CWE-345","CWE-345 CWE-345: Insufficient Verification of Data Authenticity"],"metrics":[{"version":"3.1","source":"sep@nlnetlabs.nl","type":"Secondary","score":"4.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"CNA","type":"CVSS","score":"4.4","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N","data":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}}],"references":[{"url":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-77955.txt","name":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-77955.txt","refsource":"sep@nlnetlabs.nl","tags":["Patch","Vendor Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-77955","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-77955","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"NLnet Labs","product":"Unbound","version":"affected 1.13.2 1.26.1 semver","platforms":[]}],"timeline":[{"source":"CNA","time":"2026-08-11T00:00:00.000Z","lang":"en","value":"Issue reported by Yuqi Qiu"},{"source":"CNA","time":"2026-08-16T00:00:00.000Z","lang":"en","value":"Issue reported by Qifan Zhang"},{"source":"CNA","time":"2026-08-19T00:00:00.000Z","lang":"en","value":"NLnet Labs shares patch with Yuqi Qiu"},{"source":"CNA","time":"2026-08-20T00:00:00.000Z","lang":"en","value":"Yuqi Qiu verifies patch"},{"source":"CNA","time":"2026-09-01T00:00:00.000Z","lang":"en","value":"NLnet Labs shares patch with Qifan Zhang"},{"source":"CNA","time":"2026-09-16T00:00:00.000Z","lang":"en","value":"Fixes released with version 1.26.1"}],"solutions":[{"source":"CNA","title":"","value":"This issue is fixed starting with version 1.26.1","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Yuqi Qiu (Nankai University, AOSP Lab)","lang":"en"},{"source":"CNA","value":"Xiang Li (Nankai University, AOSP Lab)","lang":"en"},{"source":"CNA","value":"Qifan Zhang (Palo Alto Networks)","lang":"en"}],"nvd_cpes":[{"cve_year":"2026","cve_id":"77955","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nlnetlabs","cpe5":"unbound","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"77955","cve":"CVE-2026-77955","epss":"0.001500000","percentile":"0.034780000","score_date":"2026-09-24","updated_at":"2026-09-25 00:02:55"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-77955","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-16T14:33:18.720420Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-16T14:33:24.961Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"Unbound","vendor":"NLnet Labs","versions":[{"lessThan":"1.26.1","status":"affected","version":"1.13.2","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Yuqi Qiu (Nankai University, AOSP Lab)"},{"lang":"en","type":"finder","value":"Xiang Li (Nankai University, AOSP Lab)"},{"lang":"en","type":"finder","value":"Qifan Zhang (Palo Alto Networks)"}],"datePublic":"2026-09-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads."}],"metrics":[{"cvssV3_1":{"baseScore":4.4,"baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"'zonemd-check: yes' configured for authoritative zones"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-345","description":"CWE-345: Insufficient Verification of Data Authenticity","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-16T08:29:39.955Z","orgId":"206fc3a0-e175-490b-9eaa-a5738056c9f6","shortName":"NLnet Labs"},"references":[{"tags":["vendor-advisory"],"url":"https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-77955.txt"}],"solutions":[{"lang":"en","value":"This issue is fixed starting with version 1.26.1"}],"timeline":[{"lang":"en","time":"2026-08-11T00:00:00.000Z","value":"Issue reported by Yuqi Qiu"},{"lang":"en","time":"2026-08-16T00:00:00.000Z","value":"Issue reported by Qifan Zhang"},{"lang":"en","time":"2026-08-19T00:00:00.000Z","value":"NLnet Labs shares patch with Yuqi Qiu"},{"lang":"en","time":"2026-08-20T00:00:00.000Z","value":"Yuqi Qiu verifies patch"},{"lang":"en","time":"2026-09-01T00:00:00.000Z","value":"NLnet Labs shares patch with Qifan Zhang"},{"lang":"en","time":"2026-09-16T00:00:00.000Z","value":"Fixes released with version 1.26.1"}],"title":"Possible ZONEMD verification bypass window","x_generator":{"engine":"cvelib 1.8.0"}}},"cveMetadata":{"assignerOrgId":"206fc3a0-e175-490b-9eaa-a5738056c9f6","assignerShortName":"NLnet Labs","cveId":"CVE-2026-77955","datePublished":"2026-09-16T08:29:39.955Z","dateReserved":"2026-09-07T14:06:21.947Z","dateUpdated":"2026-09-16T14:33:24.961Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-16 09:17:05","lastModifiedDate":"2026-09-23 20:19:28","problem_types":["CWE-345","CWE-345 CWE-345: Insufficient Verification of Data Authenticity"],"metrics":{"cvssMetricV31":[{"source":"sep@nlnetlabs.nl","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N","baseScore":4.4,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":0.7,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-16T14:33:18.720420Z","id":"CVE-2026-77955","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*","versionStartIncluding":"1.13.2","versionEndExcluding":"1.26.1","matchCriteriaId":"EC9CCE51-FB26-47DE-946F-1869093D4650"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"77955","Ordinal":"1","Title":"Possible ZONEMD verification bypass window","CVE":"CVE-2026-77955","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"77955","Ordinal":"1","NoteData":"In NLnet Labs Unbound 1.13.2 up to and including 1.26.1, a vulnerability in ZONEMD configured zones (zonemd-check: yes) which are located below (but not at) a trust anchor allow for an attack window where (tampered with) zone contents are served (or stored to disk) prior to the ZONEMD integrity check. This is caused by the needed DS/DNSKEY asynchronous resolution that needs to happen before the ZONEMD check completes. If a zonefile is written to disk (zonefile: option) while the ZONEMD check failed, the tampered data are reloaded on startup and available until ZONEMD verification concludes again. If verification fails, the data is not served any more but still persists on disk for future reloads.","Type":"Description","Title":"Possible ZONEMD verification bypass window"}]}}}