Junglewise Threat Intelligence

CVE-2026-81642: NLnet Labs Unbound DNSSEC validator buffer overflow

CVE-2026-81642 · Severity: critical · CVSS 9.8 · Published 2026-09-16

Technologies: NLnet Labs Unbound. Vendors: NLnet Labs.

Executive brief

Unbound is a widely-used DNS resolver that validates domain ownership and authenticity through DNSSEC. A buffer overflow vulnerability in the DNSSEC validator can be triggered by a malicious DNS zone, allowing an attacker to cause service outages or potentially execute arbitrary code on the server. This affects all installations running Unbound 1.26.0 and earlier.

Technical details

The vulnerability is a buffer overflow in the DNSSEC validator's DNSKEY digestion logic. A specially crafted DNSKEY record containing an owner compression pointer to its own RDATA section can overflow the digest buffer during decompression, before a capacity check is performed. The attack requires network reachability to the vulnerable Unbound instance and control of a malicious DNS zone; an attacker can trigger the overflow by querying the resolver for records in their controlled zone. Exploitation enables both denial of service and remote code execution through attacker-controlled data. Patched versions (Unbound 1.26.1 and later) include proper capacity validation after decompression to prevent the overflow.

Affected products

  • NLnet Labs Unbound up to and including 1.26.0

Timeline

  • 2026-09-16: disclosed

References

Related threats