Find notable cyber news and cases, enriched with sources, timelines, and signals.

Unbound DNSSEC validator heap overflow remote code execution flaw (CVE-2026-81642)

Vulnerability
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

A critical heap overflow in the Unbound DNSSEC validator affects Unbound DNS resolver versions up to 1.26.0, creating denial-of-service and possible remote code execution risk. An attacker who controls a malicious DNS zone can trigger the flaw by querying a vulnerable resolver. Unbound 1.26.1 fixes the bug, and no exploitation had been reported at the time of the advisory.

Related Happenings

Unbound CNAME synthesis heap corruption remote code execution flaw (CVE-2026-82717)

Vulnerability
H score33 First: 17.09.2026 15:30 Last: 17.09.2026 15:30 Sources 1

How related: One of the eight, CVE-2026-82717, is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic.

About this happening: Unbound versions up to 1.26.0 contain CVE-2026-82717, a heap corruption flaw in CNAME synthesis that can create remote code execution risk on affected buil...

Timeline

  1. 17.09.2026 15:30 1 articles · 2h ago

    Yuqi Qiu reports an Unbound DNSSEC validator heap overflow

    Initial Disclosure

    Yuqi Qiu reported a critical heap overflow in the Unbound DNS resolver's DNSSEC validator to NLnet Labs on August 11 after finding it with Xiang Li at Nankai University's AOSP Lab. The flaw could be triggered by querying a vulnerable resolver with a malicious zone and could lead to remote code execution.

    Show sources
  2. 17.09.2026 15:30 1 articles · 2h ago

    NLnet Labs shares a patch for the Unbound DNSSEC validator flaw

    Mitigation Patch Update

    NLnet Labs shared a patch for the Unbound DNSSEC validator heap overflow the next day, starting remediation for the flaw that can be triggered when a vulnerable resolver queries a malicious zone.

    Show sources
  3. 17.09.2026 15:30 2 articles · 2h ago

    NLnet Labs releases Unbound 1.26.1 and warns of CVE-2026-81642

    Initial Disclosure

    NLnet Labs released Unbound 1.26.1 and publicly warned that every release before 1.26.1 contains a critical heap overflow in its DNSSEC validator, tracked as CVE-2026-81642. The advisory says a malicious zone and query can trigger the bug, with denial of service and possible remote code execution, and notes no reported exploitation.

    Show sources