๐Ÿ” CVE Alert

CVE-2026-12490

UNKNOWN 0.0

Bypass of client certificate verification with transfer over TLS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.

CWE CWE-306 CWE-284
Vendor nlnet labs
Product nsd
Published Jun 25, 2026
Last Updated Jun 25, 2026
Stay Ahead of the Next One

Get instant alerts for nlnet labs nsd

Be the first to know when new unknown vulnerabilities affecting nlnet labs nsd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

NLnet Labs / NSD
4.10.1 < 4.14.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
nlnetlabs.nl: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txt

Credits

Qifan Zhang from Palo Alto Networks