MEDIUM

CVE-2026-42390

2026-06-25 CVSS v3.1
CVSS
5.3

Description

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

Summary dbcve.org

ZONEMD (zone message digest) validation in ZoneToCache contains a logic flaw that allows invalid zones to pass integrity checks when they should be rejected. This is a validation bypass where the cryptographic verification incorrectly returns success for zones that fail proper validation criteria.

Mitigation

Apply the vendor patch when available. Until then, evaluate whether ZoneToCache with ZONEMD validation is mission-critical; consider disabling ZONEMD validation or avoiding ZoneToCache for affected deployments.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

0.21%
Probability of exploitation in next 30 days
10.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE