Unbound DNSSEC heap overflow and CoreDNS auth bypass disclosed
Unbound's recursive resolver has a heap overflow (CVE-2026-81642, CWE-122): a DNSKEY record with a compression pointer into its own RDATA overflows the digest buffer, with RCE possible via attacker-controlled data. The fix is 1.26.1, released September 16, which also closes CVE-2026-81634 and CVE-2026-82717. CoreDNS CVE-2026-86003 (CVSS 7.5) lets encrypted transports DoH, DoQ, HTTP/3 and gRPC accept unauthenticated DNS UPDATEs; fixed in 1.14.7.
- Unbound: all releases through 1.26.0 affected, fix in 1.26.1
- CVE-2026-81642 is a heap overflow with possible RCE via attacker data
- CoreDNS: DoH, DoQ, HTTP/3 and gRPC accept unauthenticated DNS UPDATEs
- No public exploit or KEV listing as of publication
Read next
Security