Home Β· Wiki Β· Vulnerabilities & CVEs
type: cve Β· created: 2026-09-18 Β· updated: 2026-09-18 Β· tags: [cve, denial-of-service, remote-code-execution] Β· confidence: medium Β· severity: critical Β· affected_sectors: [global] Β· au_impact: false

A heap overflow in the Unbound DNS resolver's DNSSEC validator, affecting every release up to and including 1.26.0. NVD records it as awaiting analysis with a score of 9.1 (Critical, CVSS 4.0); the maintainer NLnet Labs rates it Critical and lists denial of service as the impact with remote code execution possible through attacker-controlled data.

Attribute Detail
CVE CVE-2026-81642
CVSS 9.1 (Critical, CVSS 4.0)
Vendor / product NLnet Labs / Unbound DNS resolver up to and including 1.26.0
Reported 2026-09-17

The overflow occurs while the validator digests a DNSKEY record whose owner name is a compression pointer into the record's own data. An attacker who controls a malicious zone and queries a vulnerable resolver triggers it, and the advisory attaches no configuration condition to the affected range. Unbound 1.26.1 fixes this and eight other flaws; standalone patches for 1.26.0 are published and tested. NLnet Labs reports no exploitation, and CISA's KEV entry marked exploitation as "none" at publication. Because Unbound is widely deployed as a recursive resolver across ISP, enterprise and distribution stacks, the patch is the operational priority β€” Debian had marked the fix only in unstable at the time of disclosure.