CVE-2026-54478

LOW

DNS Cookie bypass when combined with proxy-protocol use

Title source: cna
STIX 2.1

Description

In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with 'answer-cookie: yes', the RFC 9018 server-cookie SipHash is computed over the proxy's wire address instead of the PROXYv2-declared client. One server cookie obtained through a given proxy node therefore validates for every PROXYv2-declared source behind that node. On a UDP+proxy-protocol front, an off-path attacker can harvest one cookie with a single legitimate query, then replay it under any spoofed source and pass DNS Cookie checks that were deployed to defeat this in the first place.

References (1)

Core 1
Core References

Scores

CVSS v3 3.7
EPSS 0.0018
EPSS Percentile 7.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-290
Status published
Products (2)
NLnet Labs/Unbound 1.18.0 - 1.25.2
nlnetlabs/unbound 1.18.0 - 1.25.2
Published Jul 22, 2026
Tracked Since Jul 22, 2026