A critical heap overflow in the DNSSEC validator of Unbound DNS can allow an attacker controlling a malicious DNS zone to trigger a vulnerable resolver, potentially leading to remote code execution. The issue affects every Unbound release through 1.26.0.
NLnet Labs disclosed the vulnerability on September 16, 2026, and released Unbound 1.26.1 the same day. The flaw is tracked as CVE-2026-81642 and was fixed alongside eight other security issues.
DNSKEY processing flaw affects versions through 1.26.0
The overflow occurs when the validator processes a DNSKEY record whose owner name is a compression pointer into the record’s own data. According to NLnet Labs, exploitation requires an attacker to control a malicious zone and query the vulnerable resolver.
The maintainer lists denial of service as the impact, with remote code execution possible through attacker-controlled data. Its scoring describes a network-reachable issue requiring no privileges or user interaction. NLnet Labs rates it Critical and gives it a CVSS score of 4.0 (9.1); the 9.1 score is the maintainer’s own assessment, because NVD had marked the entry “Awaiting Analysis.”
NLnet Labs has not reported exploitation of this vulnerability. CISA’s entry for CVE-2026-81642 listed exploitation as “none” on September 16. The advisory does not specify whether the issue remains reachable when DNSSEC validation is disabled.
Separate CNAME flaw also permits possible code execution
Version 1.26.1 also addresses CVE-2026-82717, a High-severity heap corruption bug in CNAME synthesis. The issue was reported by Ben Morris of Anthropic and can result in code execution “under certain systems and compilation options,” according to NLnet Labs. Denial of service is also listed as an impact.
The release includes fixes for seven additional CVEs. They cover conditions involving oversized TCP responses, ZONEMD validation, QUIC and HTTP/2 builds, sustained streams of uncached names, algorithmic-complexity attacks, and the serve-expired code path. The affected version ranges vary by issue, but all are addressed in 1.26.1.
Upgrade or apply the available patches
Administrators should upgrade to Unbound 1.26.1, which is available as source code with checksums and a PGP signature, as well as Windows installers and binaries. NLnet Labs also provides standalone and combined source patches. The standalone patches for CVE-2026-81642 and CVE-2026-82717 were tested on version 1.26.0.
The earlier Critical validator issue CVE-2026-33278 is a different vulnerability. The 1.25.1 release that fixed it does not address CVE-2026-81642. Debian’s security tracker listed unbound 1.26.1-1 as fixed in unstable, while its bookworm, trixie, and forky branches were still listed as vulnerable.
Reported in August and fixed in the 1.26.1 batch
Yuqi Qiu, working with Xiang Li at Nankai University’s AOSP Lab, reported the DNSKEY flaw to NLnet Labs on August 11. The maintainer shared a patch the following day, and the reporter verified it on August 13. The fix was released about five weeks later as part of Unbound 1.26.1.
Original source: thehackernews.com
This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.








