Description
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.
Published: 2026-09-16
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Unbound, a DNS resolver that performs DNSSEC validation, contains a heap buffer overflow in its digest processing of DNSKEY records. When a DNSKEY includes a compression pointer that references its own RDATA, the digest buffer overflows, corrupting memory and potentially allowing arbitrary code execution or denial of service. The CVE explicitly states that attacker‑controlled data can trigger this overflow, leading to remote code execution.

Affected Systems

Unbound releases up to and including version 1.26.0 are affected. Deployments that act as DNS resolvers—whether public or private—running any of those versions are at risk.

Risk and Exploitability

The CVSS score of 9.1 indicates a high‑severity flaw, while the EPSS score of < 1 % suggests a low but nonzero probability of observed exploitation. The vulnerability is exposed to any external client that can query the resolver with malicious zone data. Based on the description, it is inferred that the attacker must control a zone that the resolver validates in order to supply the crafted DNSKEY and trigger the overflow. As Unbound is often exposed on the public network, the attack surface is large. The likely attack vector is a remote query from an attacker who can serve a malicious zone to the resolver. The flaw is not yet listed in the CISA KEV catalog.

Generated by OpenCVE AI on September 18, 2026 at 12:32 UTC.

Remediation

Vendor Solution

This issue is fixed starting with version 1.26.1


OpenCVE Recommended Actions

  • Upgrade Unbound to version 1.26.1 or later to apply the vendor fix.
  • Restrict the resolver's listening interfaces to trusted networks and configure firewall or ACL rules to block unsolicited queries from the broader Internet.
  • Monitor DNS query logs for unusually large DNSKEY records and suspend or drop zones that contain suspicious RDATA patterns until the patch is deployed.

Generated by OpenCVE AI on September 18, 2026 at 12:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6507-1 unbound security update
Ubuntu USN Ubuntu USN USN-8873-1 Unbound vulnerabilities
History

Tue, 22 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Critical


Thu, 17 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Nlnetlabs
Nlnetlabs unbound
Vendors & Products Nlnetlabs
Nlnetlabs unbound

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.
Title Heap buffer overflow and possible Remote Code Execution when digesting DNSKEY
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 9.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/U:Red'}


Subscriptions

Nlnetlabs Unbound
cve-icon MITRE

Status: PUBLISHED

Assigner: NLnet Labs

Published:

Updated: 2026-09-16T14:32:16.825Z

Reserved: 2026-09-07T14:06:21.956Z

Link: CVE-2026-81642

cve-icon Vulnrichment

Updated: 2026-09-16T14:30:26.931Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T09:17:06.320

Modified: 2026-09-22T18:59:21.953

Link: CVE-2026-81642

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-16T08:30:58Z

Links: CVE-2026-81642 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T12:45:08Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow