Home Β· Wiki Β· Vulnerabilities & CVEs
type: cve Β· created: 2026-09-18 Β· updated: 2026-09-18 Β· tags: [cve, denial-of-service, remote-code-execution] Β· confidence: medium Β· severity: high Β· affected_sectors: [global] Β· au_impact: false

A heap-corruption flaw in Unbound's CNAME synthesis, affecting every release up to and including 1.26.0 and fixed in 1.26.1. NVD records it as awaiting analysis with a score of 8.4 (High, CVSS 4.0); NLnet Labs rates it High and says it can progressively corrupt heap memory and, under certain systems and compilation options, lead to remote code execution.

Attribute Detail
CVE CVE-2026-82717
CVSS 8.4 (High, CVSS 4.0)
Vendor / product NLnet Labs / Unbound DNS resolver up to and including 1.26.0
Reported 2026-09-17

The corruption begins when CNAME synthesis during an upstream response has to enforce a limit, meaning the trigger sits in ordinary resolver behaviour rather than in attacker-supplied input alone. The bug was reported by Ben Morris of Anthropic and shipped in the same 1.26.1 batch as CVE-2026-81642; NLnet Labs reports no exploitation of either flaw. Operators who cannot take the full release can apply the combined patch for all nine fixes to a 1.26.0 source tree.