---
title: "CVE-2026-44690\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2026-44690?format=md
keywords: index, follow
---

# CVE-2026-44690

Publication date 22 July 2026

Last updated 6 August 2026

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.5 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2026-44690?format=md#impact-score)

Toggle side navigation

## Description

In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, insufficient
validation of the RRSIG.Labels field combined with premature cache writes
during RFC 8198 aggressive NSEC processing leads to cache poisoning that
permits a malicious actor controlling a single delegated zone to poison
arbitrary sibling zones under NSEC-signed parent domains. A malicious actor
with one registered domain under an NSEC-signed TLD can serve malicious
insecure DNS responses for unrelated sibling domains (sharing the same
parent zone). Arbitrary delegations that do not exist under the parent
domain and are covered by the parent's NSEC chain can be brought into
insecure existence by fraudulent wildcard DS records (less labels than
expected, unknown algorithm) from the malicious sibling domain. This allows
the malicious actor to inject insecure wildcard records for those
delegations.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| unbound | 26.04 LTS resolute | Needs evaluation |
| 24.04 LTS noble | Needs evaluation |
| 22.04 LTS jammy | Needs evaluation |
| 20.04 LTS focal | Needs evaluation |
| 18.04 LTS bionic | Needs evaluation |
| 16.04 LTS xenial | Needs evaluation |
| 14.04 LTS trusty | Needs evaluation |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.5 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | High |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.5 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-44690)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2026-44690)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2026-44690)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2026-44690)

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2026-44690>
* <https://community.nlnetlabs.nl/t/unbound-1-25-2-released/3430>
