Unbound, a popular DNS resolver, was found to have a critical heap overflow vulnerability in its DNSSEC validator. This vulnerability, tracked as CVE-2026-81642, could potentially lead to remote code execution. It affects all versions prior to 1.26.1, which was released to address this issue along with eight other flaws.
The exploit can occur when an attacker controls a malicious zone and queries the vulnerable resolver. NLnet Labs, the maintainer of Unbound, rates the severity of this vulnerability as Critical, with a CVSS score of 4.0 (9.1). While there have been no reported exploits yet, it is crucial for users to update to the latest version to mitigate the risk.
Aside from CVE-2026-81642, another significant flaw fixed in the latest release is CVE-2026-82717, a heap corruption bug in CNAME synthesis. This bug, reported by Ben Morris of Anthropic, also has the potential for remote code execution under certain conditions.
It is recommended for users to upgrade to Unbound 1.26.1 to patch these vulnerabilities. If upgrading is not immediately possible, users can apply the provided patches to secure their systems. NLnet Labs emphasizes the importance of staying up to date with security patches to prevent exploitation.
For more information on the specific vulnerabilities addressed in the latest release, refer to the release notes provided by NLnet Labs. It is essential for all users of Unbound to be aware of these security issues and take necessary actions to protect their systems.




