{"id":"AZL-92928","summary":"CVE-2026-50248 affecting package unbound for versions less than 1.25.2-1","details":"In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.","modified":"2026-08-28T17:47:12.002696942Z","published":"2026-07-22T14:17:20Z","upstream":["CVE-2026-50248"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-50248"}],"affected":[{"package":{"name":"unbound","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/unbound"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.25.2-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92928.json"}}],"schema_version":"1.9.0"}