Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
NLnet Labs reported a critical heap overflow in the DNSSEC validator of all versions of the Unbound DNS resolver before 1.26.1. An attacker with control over a malicious zone could cause remote code execution; the vulnerability CVE-2026-81642 is fixed in version 1.26.1.
- Vulnerability CVE-2026-81642 is a heap overflow in the DNSSEC validator
- All Unbound versions before 1.26.1 are affected
- Exploitation possible via a malicious DNS zone and leads to RCE
- Fix released in Unbound 1.26.1 on the same day
Read next
Security