Skip to content
VulniPulse
Highest advisory severityLow 1 vendor · 1 advisory

CVE-2026-46582

CVE-2026-46582: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityLow3.7

    Low [CVE-2026-46582] Information disclosure via DNSSEC wildcard replay

    CVE-2026-46582Source published Source updated

    In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation. When the resolving thread puts secure on the rrset, and another thread that is on the serve expired path then picks up the updated rrset contents with the secure status for a reply, it can be used to change a specific record, next to a wildcard that could be covered by the wildcard, into the wildcard. A malicious actor can exploit the possible poisonous effect by having any DNSSEC-singed domain (irrelevant to the victim domain) and a CNAME wrapper record that points to a record next to a wildcard (that could be…

    Affected products in this advisory
    • Red Hat Hardened Images
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 6
    • Red Hat Enterprise Linux 7

    4 more entries in the full advisory.

    Source-reported affected versions
    • < 1.6.0
    • < 1.25.1
    Source-reported fixed versions
    • unbound-main-1.25.2-0.1.hum1
    • RHSA-2026:43588
    Mitigation guidance
    • To mitigate this issue, disable the serve-expired feature by setting serve-expired: no in the Unbound configuration if it is not strictly required. This entirely removes the vulnerable code path where the cache poisoning occurs.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery