CVE-2026-39155 Details
Description
Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service.
A vulnerability exists in Knot DNS versions prior to 3.4.10 and 3.5.x prior to 3.5.4, specifically within the mod-onlinesign module. The issue arises from an incorrect computation of the next NSEC owner name, which can create an excessively broad authenticated denial interval. This flaw allows downstream validating resolvers that use aggressive negative caching to generate negative responses for legitimate names, resulting in a resolver-side denial-of-service condition.
Users can upgrade to Knot DNS versions 3.4.10 or 3.5.4 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 23, 2026CISA-ADP
Assessed Jul 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.knot-dns.cz/2026-04-01-version-3410.html | [email protected] | Release NotesVendor |
| https://www.knot-dns.cz/2026-04-02-version-354.html | [email protected] | Release NotesVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Knot DNS | < 3.4.10 (semver) >= 3.5, < 3.5.4 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 23, 2026 | New CVE Received | [email protected] |
Volerion