CVE-2026-82717
published 2026-09-16CVE-2026-82717: In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and…
PriorityP263critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.78%
54.2th percentile
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Coupled with a compression pointer that points to the overwritten value and invalidates the domain name, it leads to an error path that does not properly move the buffer position and allows for the heap buffer overflow. Since this is heavily reliant on heap memory layout, results are memory corruption that eventually leads to a crash and under specific systems and compilation options remote code execution.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | < 1.26.1 | 1.26.1 |
| nlnetlabs | unbound | < 1.26.1 | 1.26.1 |
| openshift | ose-rhel-coreos-8 | — | — |
| openshift | ose-rhel-coreos-9 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.4HIGHCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.4HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis
vendor_redhat·2026-09-16·CVSS 8.4
CVE-2026-82717 [HIGH] CWE-787 unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis
unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis
A flaw was found in Unbound. A remote attacker could exploit a vulnerability during CNAME (Canonical Name) synthesis when processing an upstream DNS response. This flaw, involving improper handling of buffer positions and compression pointers, can progressively corrupt heap memory. This memory corruption can lead to a denial of service (DoS) due to a crash, and under specific conditions, it may enable remote code execution.
Package: openshift/ose-rhel-coreos-8 (Red Hat OpenShift Container Platform 4) - Affected
Package: openshift/ose-rhel-coreos-9 (Red Hat OpenShift Container Platform 4) - Affected
GHSA
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code ex
ghsa_unreviewed·2026-09-16
CVE-2026-82717 [HIGH] CWE-122 In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code ex
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Coupled with a compression pointer that points to the overwritten value and invalidates the domain name, it leads to an error path that does not properly move the buffer position and allows for the heap buffer overflow. Since this is heavily reliant on heap memory layout, results are memory corruption that eventually leads to a crash and under specific systems and compilation options remote code execution.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-82717 unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis [fedora-all]
bugzilla·2026-09-18·CVSS 8.4
CVE-2026-82717 [HIGH] CVE-2026-82717 unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis [fedora-all]
CVE-2026-82717 unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Coupled with a compression pointer that points to the overwritten value and invalidates the domain name, it leads to an error
Bugzilla
CVE-2026-82717 unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis
bugzilla·2026-09-16·CVSS 8.4
CVE-2026-82717 [HIGH] CVE-2026-82717 unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis
CVE-2026-82717 unbound: Unbound: Remote Code Execution Vulnerability in CNAME Synthesis
In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in that can progressively corrupt heap memory and under certain systems and compilation options could lead to remote code execution. The vulnerability starts when CNAME synthesis during an upstream response needs to enforce(rewrite) a max TTL value in the packet buffer. Coupled with a compression pointer that points to the overwritten value and invalidates the domain name, it leads to an error path that does not properly move the buffer position and allows for the heap buffer overflow. Since this is heavily reliant on heap memory layout, results are memory corruption that eventually leads to a crash and under specific systems a
Hackernews
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
blogs_hackernews·2026-09-21·CVSS 10.0
CVE-2026-76460 [CRITICAL] ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.
The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not always more clarity.
Nothing here needs much drama. Just a lot of small doors left open. Here’s what happened.
## ⚡ Threat of the Week
C
Hackernews
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
blogs_hackernews·2026-09-17·CVSS 9.8
CVE-2026-81642 [CRITICAL] Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws. One of the eight, CVE-2026-82717 , is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code
2026-09-16
Published