MEDIUM
CVE-2026-42390
CVSS
5.3
Description
An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.
Summary dbcve.org
ZONEMD (zone message digest) validation in ZoneToCache contains a logic flaw that allows invalid zones to pass integrity checks when they should be rejected. This is a validation bypass where the cryptographic verification incorrectly returns success for zones that fail proper validation criteria.
Mitigation
Apply the vendor patch when available. Until then, evaluate whether ZoneToCache with ZONEMD validation is mission-critical; consider disabling ZONEMD validation or avoiding ZoneToCache for affected deployments.
Weakness (CWE)
CWE-20
Improper Input Validation
EPSS Score
0.21%
Probability of exploitation in next 30 days
10.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.