CYBER DELTA FORCESearch

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

CDF News DeskThe Hacker News17 Sept 2026, 6:00 pm
Image courtesy of The Hacker News. Original report
CDF REPORT

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.

Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws.

It could also lead to remote code execution "under certain systems and compilation options," NLnet Labs said.

The Critical validator bug NLnet Labs fixed in May, CVE-2026-33278 , is a different flaw, and the 1.25.1 update that fixed it does not fix this one.

Debian's security tracker listed unbound 1.26.1-1 as fixed in unstable on Thursday, with the bookworm, trixie, and forky branches still listed as vulnerable.

Unbound 1.26.1 is available as source, with checksums and a PGP signature, and as Windows installers and binaries.

The ReTrap fix also changes a default: val-clean-more is now off, so Unbound no longer validates DNSSEC data in the more section of a response by default.

What happened

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.

Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws.

Who is affected

It could also lead to remote code execution "under certain systems and compilation options," NLnet Labs said.

Technical details

The Critical validator bug NLnet Labs fixed in May, CVE-2026-33278 , is a different flaw, and the 1.25.1 update that fixed it does not fix this one.

Debian's security tracker listed unbound 1.26.1-1 as fixed in unstable on Thursday, with the bookworm, trixie, and forky branches still listed as vulnerable.

Response

Unbound 1.26.1 is available as source, with checksums and a PGP signature, and as Windows installers and binaries.

The ReTrap fix also changes a default: val-clean-more is now off, so Unbound no longer validates DNSSEC data in the more section of a response by default.

What remains unknown

NLnet Labs attaches no configuration condition to that range, and it has not said whether a resolver with DNSSEC validation switched off is reachable.

Attribution

The Hacker News: Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

What to watch next

Watch for revised vendor guidance, fixed versions and mitigation updates.

MORE IN POLICY

More cybersecurity reporting

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host FilesThe Hacker News · 17 Sept 2026, 9:07 pm