NLnet Labs has warned that every Release of the Unbound DNS resolver before 1.26.1 contains a critical heap overflow in its DNSSEC validator that an attacker who controls a malicious zone can trigger by querying a vulnerable resolver, enabling remote code execution. The bug, CVE-2026-81642, occurs while the validator digests a DNSKEY record whose owner name is a compression pointer into the record's own data; NLnet rates it Critical with a CVSS score of 9.1 and no privilege or interaction requirement. Unbound 1.26.1, released the same day, fixes it along with eight other flaws, including CVE-2026-82717, a high-severity heap-corruption bug in CNAME synthesis (reported by Ben Morris of Anthropic) that can also lead to RCE under certain compilation options. NLnet reports no exploitation of either bug, and CISA's KEV entry marked exploitation of CVE-2026-81642 as "none" on Wednesday. The fix also changes a default β val-clean-additional is now off, so Unbound no longer validates DNSSEC data in the additional section by default. Given Unbound's widespread use as a recursive resolver across ISPs, enterprises and distro stacks, the patch is the operational priority; Debian has so far only marked the fix in unstable.
| Attribute | Detail |
|---|---|
| Sector | Global (Macro) |
| Date | 2026-09-18 |
| Source | The Hacker News |
| Reliability | Tier 2 |
| CVEs | CVE-2026-81642, CVE-2026-82717 |