← Vulnerability feed

Vulnerability record · CVE-2026-12490 · published 25 June 2026

CVE-2026-12490: Nlnetlabs nsd improper access control vulnerability

Nlnetlabs · Nsd

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.

8.2 CVSS 4.0 High EPSS 0.22% · top 89.1% CWE-284 · Improper access controlCWE-306 · Missing authentication for critical function
8.2CVSS 4.0 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
26 Jun 2026Last modified by NVD

Description

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-12490 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-12245Nlnetlabs nsd use after free vulnerabilityNSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be trigg…EPSS 0.46%8.7CVE-2026-12244Nlnetlabs nsd heap-based buffer overflow vulnerabilityIf NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVC…EPSS 0.49%8.2CVE-2026-19538Nlnetlabs nsd authentication bypass by spoofing vulnerabilityThe BLOCKED access control list items that are evaluated to deny access on the the proxy protocol port can be bypassed completely when connecting ove…EPSS 0.23%8.2CVE-2026-18664Nlnetlabs nsd improper access control vulnerabilityWhen ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address with the range on little end…EPSS 0.26%8.2CVE-2026-19401Nlnetlabs nsd uncontrolled resource consumption vulnerabilityAny remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message with a specially tuned numbe…EPSS 0.28%7.5CVE-2016-6173Nlnetlabs nsd vulnerabilityNSD before 4.1.11 allows remote DNS master servers to cause a denial of service (/tmp disk consumption and slave server crash) via a zone transfer wi…EPSS 2.9%7.2CVE-2026-12246Nlnetlabs nsd improper input validation vulnerabilityNSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite t…EPSS 0.44%6.9CVE-2026-18916Nlnetlabs nsd vulnerabilityAny remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously crashing the serve childs, the…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2026-12490), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.