{"id":"CVE-2019-25031","title":"Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session","summary":"Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound softw…","severity":"medium","cvss":5.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-74"],"vendor":"nlnetlabs","product":"unbound","affected":["unbound < 1.9.5","debian_linux = 9.0"],"patched":["unbound 1.9.5"],"published":"2021-04-27","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2019-25031","references":[{"url":"https://lists.debian.org/debian-lts-announce/2021/05/msg00007.html","label":"cve@mitre.org"},{"url":"https://ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20210507-0007/","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/05/msg00007.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ostif.org/our-audit-of-unbound-dns-by-x41-d-sec-full-results/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20210507-0007/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.01339,"epssPercentile":0.70038,"ingestedAt":"2026-08-25T11:24:50.575Z","slug":"CVE-2019-25031","body":"## Overview\n\nUnbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation\n\n## Affected\n\n- `unbound < 1.9.5`\n- `debian_linux = 9.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `unbound 1.9.5`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":32.5,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}