CVE-2026-12490
Description
A flaw was found in nsd. When a 'provide-xfr' is configured with a 'tls-auth-name', the server incorrectly allows zone transfers without requiring a client certificate if the request comes over TLS on the regular 'tls-port' or over TCP on the regular port, provided other access control conditions are met. This authentication bypass allows an attacker to perform unauthorized zone transfers, leading to information disclosure.
Statement
This flaw is rated as Moderate. The nsd DNS server, when configured for zone transfers with provide-xfr and tls-auth-name, can bypass client certificate verification. This allows unauthorized zone transfers and information disclosure if requests are made over the regular TLS or TCP port, as the tls-auth-xfr-only option is not enabled by default.
This vulnerability doesn't affect any supported Red Hat Product.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Bypass Protection Mechanism
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.