DKDKCISSPSearch
Policy

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

DKCISSP News DeskThe Hacker News17 Sept 2026, 6:00 pm
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Image courtesy of The Hacker News. Original report
DKCISSP REPORT

NLnet Labs disclosed a critical heap-overflow vulnerability in the DNSSEC validation code used by Unbound, an open-source recursive DNS resolver. CVE-2026-81642 affects releases through Unbound 1.26.0.

An attacker must control a malicious DNS zone and get a vulnerable resolver to process attacker-controlled DNS data. NLnet Labs says the defect can cause denial of service and that remote code execution is possible through attacker-controlled data.

Unbound 1.26.1 was released with the fix and also addresses eight other security issues. CVE-2026-82717, another issue in the same release, affects CNAME synthesis and can also lead to remote code execution under certain conditions.

Resolvers sit in the path of normal name resolution, so a flaw reachable through attacker-controlled DNS data can turn trusted infrastructure into an attack surface.

The technical trigger involves how the validator processes a DNSKEY record whose owner name is a compression pointer into the record's own data, driving the heap-overflow condition during DNSSEC processing.

Security teams should inventory Unbound versions and move to 1.26.1 where possible. If an upgrade is delayed, evaluate the vendor-provided patches and verify the resulting build before returning it to service.

NLnet Labs has not reported exploitation of CVE-2026-81642, so defenders should distinguish the current patch requirement from any claim that the flaw is being exploited in the wild.

What happened

NLnet Labs disclosed a critical heap-overflow vulnerability in the DNSSEC validation code used by Unbound, an open-source recursive DNS resolver. CVE-2026-81642 affects releases through Unbound 1.26.0.

An attacker must control a malicious DNS zone and get a vulnerable resolver to process attacker-controlled DNS data. NLnet Labs says the defect can cause denial of service and that remote code execution is possible through attacker-controlled data.

What changed

Unbound 1.26.1 was released with the fix and also addresses eight other security issues. CVE-2026-82717, another issue in the same release, affects CNAME synthesis and can also lead to remote code execution under certain conditions.

The vulnerable range includes Unbound 1.25.2 and 1.26.0. A separate critical DNSSEC issue fixed in May is not the same vulnerability and does not replace this update.

Who is affected

Organizations operating Unbound recursive resolvers on versions 1.26.0 and earlier are in the affected range. Public reporting does not establish that a particular DNSSEC configuration removes the vulnerable code path.

Why it matters

Resolvers sit in the path of normal name resolution, so a flaw reachable through attacker-controlled DNS data can turn trusted infrastructure into an attack surface.

Technical details

The trigger involves how the validator processes a DNSKEY record whose owner name is a compression pointer into the record's own data, driving the heap-overflow condition during DNSSEC processing.

NLnet Labs assigned a 9.1 CVSS score and described the issue as network-reachable without privileges or user interaction. NVD had not completed its own analysis at the time of the report.

Response

Unbound 1.26.1 is available as source as well as Windows installers and binaries. NLnet Labs also provides standalone and combined source patches for affected installations that cannot immediately upgrade.

What security teams should do

Inventory Unbound versions and move to 1.26.1 where possible. If an upgrade is delayed, evaluate the vendor-provided patches and verify the resulting build before returning it to service.

Review resolver telemetry for abnormal DNS activity and keep recursive DNS infrastructure under the same monitoring and change-control discipline used for other security-sensitive services.

What remains unknown

NLnet Labs has not reported exploitation of CVE-2026-81642, and public reporting does not establish whether disabling DNSSEC validation removes the vulnerable code path.

Attribution

The Hacker News reported the NLnet Labs advisory and the release of Unbound 1.26.1.

What to watch next

Watch for updated vendor guidance, distribution-specific fixed packages and any credible reports of exploitation.

MORE IN POLICY

More cybersecurity reporting

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host FilesThe Hacker News · 17 Sept 2026, 9:07 pmNIS Directive has Positive Effect, though Study Finds Gaps in Cybersecurity Investment Exist | ENISAENISA · 27 Aug 2026, 7:10 pm