chiprook
← Security
SecurityOctober 4, 2026, 08:12

Unbound DNSSEC heap overflow and CoreDNS auth bypass disclosed

Unbound's recursive resolver has a heap overflow (CVE-2026-81642, CWE-122): a DNSKEY record with a compression pointer into its own RDATA overflows the digest buffer, with RCE possible via attacker-controlled data. The fix is 1.26.1, released September 16, which also closes CVE-2026-81634 and CVE-2026-82717. CoreDNS CVE-2026-86003 (CVSS 7.5) lets encrypted transports DoH, DoQ, HTTP/3 and gRPC accept unauthenticated DNS UPDATEs; fixed in 1.14.7.

Unbound DNSSEC heap overflow and CoreDNS auth bypass disclosed
#Unbound#CoreDNS
Read next
Security

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Security

CTranslate2 CVE-2026-102566 & CVE-2026-102567: Heap Overflow in AI Model Loader

Security

CVE-2026-8452 in Citrix NetScaler: SAML parsing overflow leads to pre-auth RCE

Security

Ghost CMS discloses six CVEs, including CVSS 8.1 staff session bypass