Low severity3.7OSV Advisory· Published Jul 23, 2026· Updated Jul 23, 2026
CVE-2026-52686
CVE-2026-52686
Description
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
Affected products
2Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.