CVE-2026-81634
published 2026-09-16CVE-2026-81634: In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.36%
29.4th percentile
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | < 1.26.1 | 1.26.1 |
| openshift | ose-rhel-coreos-8 | — | — |
| openshift | ose-rhel-coreos-9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
unbound: Unbound: Heap buffer overflow via malicious DNSSEC response
vendor_redhat·2026-09-16·CVSS 7.5
CVE-2026-81634 [HIGH] CWE-120 unbound: Unbound: Heap buffer overflow via malicious DNSSEC response
unbound: Unbound: Heap buffer overflow via malicious DNSSEC response
A flaw was found in Unbound. This vulnerability allows a remote attacker to cause a heap buffer overflow during the processing of DNSSEC responses. By sending a specially crafted DNSSEC response, a malicious server or an attacker tampering with network traffic can trigger this flaw. This could lead to a denial of service, making the Unbound service unavailable.
Package: openshift/ose-rhel-coreos-8 (Red Hat OpenShift Container Platform 4) - Affected
Package: openshift/ose-rhel-coreos-9 (Red Hat OpenShift Container Platform 4) - Affected
GHSA
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine.
ghsa_unreviewed·2026-09-16
CVE-2026-81634 [HIGH] CWE-122 In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine.
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-81634 unbound: Unbound: Heap buffer overflow via malicious DNSSEC response [fedora-all]
bugzilla·2026-09-18·CVSS 7.5
CVE-2026-81634 [HIGH] CVE-2026-81634 unbound: Unbound: Heap buffer overflow via malicious DNSSEC response [fedora-all]
CVE-2026-81634 unbound: Unbound: Heap buffer overflow via malicious DNSSEC response [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.
Bugzilla
CVE-2026-81634 unbound: Unbound: Heap buffer overflow via malicious DNSSEC response
bugzilla·2026-09-16·CVSS 7.5
CVE-2026-81634 [HIGH] CVE-2026-81634 unbound: Unbound: Heap buffer overflow via malicious DNSSEC response
CVE-2026-81634 unbound: Unbound: Heap buffer overflow via malicious DNSSEC response
In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.
Hackernews
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
blogs_hackernews·2026-09-17·CVSS 9.8
CVE-2026-81642 [CRITICAL] Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws. One of the eight, CVE-2026-82717 , is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code
2026-09-16
Published