Unbound CNAME synthesis heap corruption remote code execution flaw (CVE-2026-82717)
Vulnerability
Summary
Hide ▲
Show ▼
Unbound versions up to 1.26.0 contain CVE-2026-82717, a heap corruption flaw in CNAME synthesis that can create remote code execution risk on affected builds. The vulnerability is fixed in Unbound 1.26.1, and NLnet Labs said the bug could affect some systems and compilation options. NLnet Labs did not report exploitation of this flaw.
Related Happenings
Unbound DNSSEC validator heap overflow remote code execution flaw (CVE-2026-81642)
Vulnerability
H score33
First: 17.09.2026 15:30
Last: 17.09.2026 15:30
Sources 1
How related:
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
About this happening:
A critical heap overflow in the Unbound DNSSEC validator affects Unbound DNS resolver versions up to 1.26.0, creating denial-of-service and possible remote c...
Unbound DNSSEC validator heap overflow remote code execution flaw (CVE-2026-81642)
VulnerabilityHow related: Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
About this happening: A critical heap overflow in the Unbound DNSSEC validator affects Unbound DNS resolver versions up to 1.26.0, creating denial-of-service and possible remote c...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
Timeline
-
17.09.2026 15:30 1 articles · 2h ago
Yuqi Qiu reports CVE-2026-82717 to NLnet Labs
Initial DisclosureYuqi Qiu reported the Unbound DNS resolver heap corruption bug tracked as CVE-2026-82717 to NLnet Labs after finding it with Xiang Li at Nankai University's AOSP Lab.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
-
17.09.2026 15:30 1 articles · 2h ago
NLnet Labs shares a patch for CVE-2026-82717
Mitigation Patch UpdateNLnet Labs shared a patch for CVE-2026-82717 on August 12, addressing the Unbound DNS resolver CNAME synthesis heap corruption flaw.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
-
17.09.2026 15:30 1 articles · 2h ago
Reporter verifies the CVE-2026-82717 patch
Mitigation Patch UpdateYuqi Qiu verified NLnet Labs' patch for CVE-2026-82717 on August 13.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
-
17.09.2026 15:30 2 articles · 2h ago
Unbound 1.26.1 fixes CVE-2026-82717
Mitigation Patch UpdateNLnet Labs released Unbound 1.26.1, fixing CVE-2026-82717 and eight other flaws in the DNS resolver.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30