CVE-2026-42955 Details
Description
In NLnet Labs Unbound 1.16.2 up to and including 1.25.1, a similar vulnerability as with CVE-2026-40622 in the 'ghost domain names' family of attacks was found in Unbound that could extend the ghost domain window by up to one cached TTL configured value for A/AAAA glue records. Similar to other 'ghost domain names' attacks, an adversary needs to control a (ghost) zone and be able to query a vulnerable Unbound. A single client A/AAAA query can cause Unbound to overwrite the cached expired parent-side glue rrset and essentially extend the ghost domain window by up to one cached TTL configured value ('cache-max-ttl'). In configurations where 'harden-referral-path: yes' is used (non-default configuration), no client query is required since Unbound implicitly performs that query. This is a variant of CVE-2026-40622 which only addressed the NS query.
A vulnerability in NLnet Labs Unbound versions 1.16.2 prior to 1.25.1 allows for the extension of the ghost domain window by up to one cached TTL value for A/AAAA glue records. This issue, similar to CVE-2026-40622, arises in 'ghost domain names' attacks where an adversary controls a (ghost) zone and queries a vulnerable Unbound server. In affected versions, a single client A/AAAA query can overwrite the cached expired parent-side glue record, extending the ghost domain window. In configurations with 'harden-referral-path: yes' (non-default), no client query is needed as Unbound automatically performs it. Unbound 1.25.2 addresses this vulnerability by preventing the extension of TTLs for A/AAAA records, regardless of their trust.
Users can upgrade to Unbound 1.25.2, which includes the necessary fix. Alternatively, for those using Unbound 1.25.1, a patch is available that addresses this vulnerability. Instructions for applying the patch are included in the Unbound 1.25.1 release notes.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-42955.txt | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-672 | Operation on a Resource after Expiration or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nlnetlabs unbound | >= 1.16.2, < 1.25.2 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | Initial Analysis | [email protected] |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |