CVE-2026-55708Nlnetlabs · Unbound
Vulnerability data via NVD (ingested)
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'view_local_data' and 'view_local_datas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-55708product:"Nlnetlabs Unbound"http.html:"Unbound"More intel sources (5)
vuln:CVE-2026-55708vulnerabilities.cve_id: CVE-2026-55708CVE-2026-55708CVE-2026-55708"CVE-2026-55708" exploit -site:nvd.nist.gov