{
  "threat_severity" : "Moderate",
  "public_date" : "2026-07-22T13:08:32Z",
  "bugzilla" : {
    "description" : "unbound: Unbound: DNS response policy replacement via hostname spoofing",
    "id" : "2506129",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2506129"
  },
  "cvss3" : {
    "cvss3_base_score" : "6.5",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L",
    "status" : "verified"
  },
  "cwe" : "CWE-345",
  "details" : [ "In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.", "A flaw in Unbound allows a remote attacker to replace an authenticated or Response Policy Zone (RPZ) by spoofing DNS records for configured primary hostnames. This enables the attacker to impersonate the primary server, leading to DNS cache poisoning or traffic redirection." ],
  "statement" : "A Moderate impact flaw in Unbound allows a remote attacker to replace a resolver's Response Policy Zone (RPZ) by spoofing A/AAAA records for configured primary hostnames. If successful, an attacker can manipulate response policies, redirect traffic, or poison the DNS cache.",
  "affected_release" : [ {
    "product_name" : "Red Hat Hardened Images",
    "release_date" : "2026-07-22T00:00:00Z",
    "advisory" : "RHSA-2026:43588",
    "cpe" : "cpe:/a:redhat:hummingbird:1",
    "package" : "unbound-main-1.25.2-0.1.hum1"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 10",
    "fix_state" : "Fix deferred",
    "package_name" : "unbound",
    "cpe" : "cpe:/o:redhat:enterprise_linux:10"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "unbound",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "unbound",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Fix deferred",
    "package_name" : "unbound",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  }, {
    "product_name" : "Red Hat Enterprise Linux 9",
    "fix_state" : "Fix deferred",
    "package_name" : "unbound",
    "cpe" : "cpe:/o:redhat:enterprise_linux:9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-8",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Fix deferred",
    "package_name" : "openshift/ose-rhel-coreos-9",
    "cpe" : "cpe:/a:redhat:openshift:4"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-50248\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-50248\nhttps://www.nlnetlabs.nl/downloads/unbound/CVE-2026-50248.txt" ],
  "name" : "CVE-2026-50248",
  "mitigation" : {
    "value" : "Configure Response Policy Zones (RPZ) and secondary zone primary endpoints using explicit IP addresses rather than hostnames to prevent A/AAAA spoofing or resolution flaws. Additionally, restrict network access for zone transfers to trusted sources and reload or restart the unbound service for configuration changes to take effect.",
    "lang" : "en:us"
  },
  "csaw" : false
}