A heap-corruption flaw in Unbound's CNAME synthesis, affecting every release up to and including 1.26.0 and fixed in 1.26.1. NVD records it as awaiting analysis with a score of 8.4 (High, CVSS 4.0); NLnet Labs rates it High and says it can progressively corrupt heap memory and, under certain systems and compilation options, lead to remote code execution.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-82717 |
| CVSS | 8.4 (High, CVSS 4.0) |
| Vendor / product | NLnet Labs / Unbound DNS resolver up to and including 1.26.0 |
| Reported | 2026-09-17 |
The corruption begins when CNAME synthesis during an upstream response has to enforce a limit, meaning the trigger sits in ordinary resolver behaviour rather than in attacker-supplied input alone. The bug was reported by Ben Morris of Anthropic and shipped in the same 1.26.1 batch as CVE-2026-81642; NLnet Labs reports no exploitation of either flaw. Operators who cannot take the full release can apply the combined patch for all nine fixes to a 1.26.0 source tree.