Unbound DNSSEC validator heap overflow remote code execution flaw (CVE-2026-81642)
Vulnerability
Summary
Hide ▲
Show ▼
A critical heap overflow in the Unbound DNSSEC validator affects Unbound DNS resolver versions up to 1.26.0, creating denial-of-service and possible remote code execution risk. An attacker who controls a malicious DNS zone can trigger the flaw by querying a vulnerable resolver. Unbound 1.26.1 fixes the bug, and no exploitation had been reported at the time of the advisory.
Related Happenings
Unbound CNAME synthesis heap corruption remote code execution flaw (CVE-2026-82717)
Vulnerability
H score33
First: 17.09.2026 15:30
Last: 17.09.2026 15:30
Sources 1
How related:
One of the eight, CVE-2026-82717, is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic.
About this happening:
Unbound versions up to 1.26.0 contain CVE-2026-82717, a heap corruption flaw in CNAME synthesis that can create remote code execution risk on affected buil...
Unbound CNAME synthesis heap corruption remote code execution flaw (CVE-2026-82717)
VulnerabilityHow related: One of the eight, CVE-2026-82717, is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic.
About this happening: Unbound versions up to 1.26.0 contain CVE-2026-82717, a heap corruption flaw in CNAME synthesis that can create remote code execution risk on affected buil...
Timeline
-
17.09.2026 15:30 1 articles · 2h ago
Yuqi Qiu reports an Unbound DNSSEC validator heap overflow
Initial DisclosureYuqi Qiu reported a critical heap overflow in the Unbound DNS resolver's DNSSEC validator to NLnet Labs on August 11 after finding it with Xiang Li at Nankai University's AOSP Lab. The flaw could be triggered by querying a vulnerable resolver with a malicious zone and could lead to remote code execution.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
-
17.09.2026 15:30 1 articles · 2h ago
NLnet Labs shares a patch for the Unbound DNSSEC validator flaw
Mitigation Patch UpdateNLnet Labs shared a patch for the Unbound DNSSEC validator heap overflow the next day, starting remediation for the flaw that can be triggered when a vulnerable resolver queries a malicious zone.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
-
17.09.2026 15:30 1 articles · 2h ago
Reporter verifies the Unbound DNSSEC validator patch
Mitigation Patch UpdateThe reporter verified NLnet Labs' patch on August 13, confirming the fix for the Unbound DNSSEC validator heap overflow.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
-
17.09.2026 15:30 2 articles · 2h ago
NLnet Labs releases Unbound 1.26.1 and warns of CVE-2026-81642
Initial DisclosureNLnet Labs released Unbound 1.26.1 and publicly warned that every release before 1.26.1 contains a critical heap overflow in its DNSSEC validator, tracked as CVE-2026-81642. The advisory says a malicious zone and query can trigger the bug, with denial of service and possible remote code execution, and notes no reported exploitation.
Show sources
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone — thehackernews.com — 17.09.2026 15:30