CVE-2026-12490

Name
CVE-2026-12490
Description
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
sep@nlnetlabs.nl https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txt

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:nlnetlabs:nsd:*:*:*:*:*:*:*:* nsd >= None < 4.14.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
nsd edge-main 4.14.3-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
nsd edge-main 4.14.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.14.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.14.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.13.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.12.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.11.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.11.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.10.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd edge-main 4.3.4-r0 None possibly vulnerable
nsd 3.24-main 4.14.3-r0 Natanael Copa <ncopa@alpinelinux.org> fixed
nsd 3.24-main 4.14.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.23-main 4.13.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.22-main 4.12.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.22-main 4.3.4-r0 None possibly vulnerable
nsd 3.21-main 4.11.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.21-main 4.11.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.21-main 4.10.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.21-main 4.3.4-r0 None possibly vulnerable
nsd 3.20-main 4.9.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.20-main 4.3.4-r0 None possibly vulnerable
nsd 3.19-main 4.7.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
nsd 3.19-main 4.3.4-r0 None possibly vulnerable