NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of attacks that could extend the ghost domain window by up to one cached TTL configured value. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client NS query can cause Unbound to overwrite the cached expired parent-side referral NS rrset with the child-side apex NS rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client NS query is required since Unbound implicitly performs that query. Unbound 1.25.1 contains a patch with a fix that does not allow extension of TTLs for (parent) NS records regardless of their trust.
CVSS Details
- CVSS 4.0 Base Score: 6.6 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Amber)
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade unbound-libsUpgrade unboundUpgrade unbound-dracutUpgrade unbound-develUpgrade python3-unbound | Aug 2, 2026 | Jul 8, 2026 |
| Alpine Linux | — | Upgrade unbound | Jun 18, 2026 | May 20, 2026 |
| Amazon Linux Ami 2 | — | Upgrade unbound-libsUpgrade unboundUpgrade unbound-anchorUpgrade unbound-utilsUpgrade unbound-develUpgrade python3-unboundUpgrade python2-unboundUpgrade unbound-debuginfo | Jul 21, 2026 | Jul 21, 2026 |
| Amazon_linux_2023 | — | Upgrade python3-unbound-debuginfoUpgrade unbound-debugsourceUpgrade unbound-anchor-debuginfoUpgrade unbound-debuginfoUpgrade unbound-develUpgrade unbound-libsUpgrade python3-unboundUpgrade unbound-utils-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-utilsUpgrade unbound-anchorUpgrade unbound | May 28, 2026 | May 20, 2026 |
| Debian | — | Upgrade unbound | Jul 23, 2026 | Jul 23, 2026 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jul 17, 2026 | Jul 16, 2026 |
| Freebsd | — | Upgrade FreeBSDUpgrade unbound | Jun 15, 2026 | Jun 10, 2026 |
| Redhat Openshift | — | Upgrade rhcos | Aug 19, 2026 | May 20, 2026 |
| Redhat_linux | — | Upgrade unbound-debuginfoUpgrade unbound-dracutNo solution existsUpgrade unbound-anchor-debuginfoUpgrade unbound-anchorUpgrade unbound-debugsourceUpgrade unboundUpgrade unbound-develUpgrade unbound-utils-debuginfoUpgrade unbound-libs-debuginfoUpgrade unbound-utilsUpgrade python3-unbound-debuginfoUpgrade unbound-libsUpgrade python3-unbound | Jul 30, 2026 | May 20, 2026 |
| Rocky_linux | — | Upgrade unbound-debuginfoUpgrade unbound-dracutUpgrade unboundUpgrade unbound-develUpgrade unbound-libsUpgrade python3-unboundUpgrade unbound-debugsourceUpgrade unbound-libs-debuginfoUpgrade python3-unbound-debuginfo | Jul 30, 2026 | Jul 28, 2026 |
| Ubuntu | — | Upgrade unboundUpgrade libunbound8 | May 25, 2026 | May 20, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jun 5, 2026 | May 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub