Unbound DNSSEC validator heap overflow CVE-2026-81642 (Critical, CVSS 9.1); fix 1.26.1
NLnet Labs advisory dated 16 September 2026 (covered by The Hacker News 17 Sep) assigns CVE-2026-81642 to a Critical heap overflow in Unbound’s DNSSEC validator when digesting a DNSKEY whose owner name is a compression pointer into its own RDATA. An attacker who controls a malicious zone and queries a vulnerable resolver can cause denial of service and possible remote code execution through attacker-controlled data. NLnet Labs rates Critical with maintainer CVSS 9.1 (CVSS:4.0 network/no privileges/no UI; NVD still awaiting analysis per THN). Affected: Unbound up to and including 1.26.0 (includes 1.25.2 and 1.26.0). Fixed: Unbound 1.26.1 (source + Windows binaries) or apply NLnet Labs patches (minimal or complete for CVE-2026-81642; combined patch covers nine CVEs in the release, including high CVE-2026-82717 CNAME-synthesis heap corruption). NLnet Labs reports no known exploitation; CISA exploitation “none” on disclosure day per THN. Primary: NLnet Labs CVE-2026-81642.txt / security advisories; wire: THN 17 Sep 2026.
- Product
- NLnet Labs Unbound DNS resolver (DNSSEC validator)
- Versions
- Affected: up to and including 1.26.0; fixed: 1.26.1 (or vendor-packaged rebuilds with NLnet Labs patches)
- CVSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H- Exploited in Australia?
- unknown
- Patch to
- Upgrade Unbound to 1.26.1 or later; if blocked, apply NLnet Labs patch_CVE-2026-81642_with.diff (or combined 1.26.1 patch) and rebuild; prioritise public recursive resolvers with DNSSEC validation
Primary: NLnet Labs — CVE-2026-81642 (Unbound DNSKEY digest overflow) · Vendor: NLnet Labs — Unbound security advisories · CVE: CVE-2026-81642, CVE-2026-82717 · THN — Unbound DNSSEC RCE via malicious zone (17 Sep 2026)
