CVE-2026-39155
Received Received - Intake

Knot DNS NSEC Owner Name Computation Flaw

Vulnerability report for CVE-2026-39155, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: MITRE

Description

Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-24
AI Q&A
2026-07-24
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
knot_dns knot_dns to 3.4.10 (exc)
knot_dns knot_dns to 3.5.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Knot DNS before versions 3.4.10 and 3.5.x before 3.5.4 has a flaw in the mod-onlinesign module where the next NSEC owner name is computed incorrectly. This leads to an overly broad authenticated denial interval, which can cause downstream validating resolvers with aggressive negative caching to generate false negative responses for valid names, resulting in a denial of service at the resolver level.

Impact Analysis

If you use a vulnerable version of Knot DNS, your DNS resolver might incorrectly block access to legitimate domain names due to synthesized negative answers. This can disrupt network services, prevent users from reaching valid websites, and cause widespread connectivity issues.

Mitigation Strategies

Upgrade Knot DNS to version 3.4.10 or later for the 3.4.x branch, or to version 3.5.4 or later for the 3.5.x branch to address the vulnerability in mod-onlinesign.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-39155. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart