CVE-2026-55708: Privacy/configuration issue when adding local data in views through 'unbound-control'

Published Jul 22, 2026
·
Updated

In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, the 'viewlocaldata' and 'viewlocaldatas' commands of 'unbound-control' create a bare local zones tree for an already configured named view when the view is configured with no local data to begin with. However, the creation through the control interface omits adding the default-protected zones (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost). Once the local zone tree exists without the defaults, every query for a default-protected name from a client mapped to that view escapes to the public DNS via the iterator instead of being answered locally, bypassing local policy expectations.

Other sources

Privacy/configuration issue when adding local data in views through 'unbound-control'

Microsoft

Affected Software

3 affected componentsFixes available
Nlnet Labs Unbound>=1.6.0<=1.25.1
Microsoft azl3 unbound 1.25.1-1<1.25.2-1
1.25.2-1
nlnetlabs Unbound>=1.6.0<1.25.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 1.25.2-1
  2. Upgrade

    Upgrade NLnet Labs Unbound to a version that resolves this vulnerability.

    Fixed in 1.25.2
  3. Compensating control

    After creating local data in a named view via unbound-control (using view_local_data/view_local_datas), ensure the default-protected local zones are present so that default-protected names (e.g., RFC 1918 reverse, AS112 zones, .onion, .localhost) are answered locally rather than escaping to public DNS via the iterator.

Event History

Jul 22, 2026
CVE Published
via MITRE·01:09 PM
Data Sourced
via MITRE·01:09 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeaknessAffected Software
Jul 23, 2026
Data Sourced
via Microsoft·08:03 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:03 AM
Affected Software
Updated
via Microsoft·08:03 AM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-55708?

The severity of CVE-2026-55708 is rated as low with a score of 3.1.

2

How do I fix CVE-2026-55708?

To mitigate CVE-2026-55708, ensure that local data is properly configured before using the 'view_local_data' and 'view_local_datas' commands in unbound-control.

3

What are the potential impacts of CVE-2026-55708?

CVE-2026-55708 may lead to configuration issues that can expose local zone data in unintended ways.

4

In which versions of Unbound is CVE-2026-55708 present?

CVE-2026-55708 affects NLnet Labs Unbound versions 1.6.0 up to and including 1.25.1.

5

What type of issue is identified in CVE-2026-55708?

CVE-2026-55708 is classified as a privacy/configuration issue related to the handling of local data in views.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203