CVE-2026-82720
published 2026-09-16CVE-2026-82720: NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'…
PriorityP432medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.29%
21.3th percentile
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If the prerequisites are satisfied (possible RPZ drop or heavy client traffic), a malicious actor can trigger the vulnerability with a single DoH connection and the appropriate traffic. Impact is limited as the reads are not user controlled and the use-after-free leads to early returns. However, a hardened allocator can catch the use-after-free and controllably terminate the process resulting to denial of service.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.12.0 < 1.26.1 | 1.26.1 |
| openshift | ose-rhel-coreos-8 | — | — |
| openshift | ose-rhel-coreos-9 | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'.
ghsa_unreviewed·2026-09-16
CVE-2026-82720 [MEDIUM] CWE-416 NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'.
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If the prerequisites are satisfied (possible RPZ drop or heavy client traffic), a malicious actor can trigger the vulnerability with a single DoH connection and the appropriate traffic. Impact is limited as the reads are not user controlled and the use-after-free leads to early returns. However, a hardened allocator can catch the use-after-free and controllably terminate the process re
Red Hat
unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup
vendor_redhat·2026-09-16·CVSS 5.9
CVE-2026-82720 [MEDIUM] CWE-825 unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup
unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup
A flaw was found in Unbound. When compiled with DNS-over-HTTPs (DoH) support, a use-after-free vulnerability exists in the DoH stream cleanup code. A remote malicious actor can exploit this by sending a specially crafted DoH connection under specific failure conditions, such as an RPZ drop query or heavy traffic. This can lead to a denial of service (DoS) by causing the Unbound process to terminate.
Package: openshift/ose-rhel-coreos-8 (Red Hat OpenShift Container Platform 4) - Fix deferred
Package: openshift/ose-rhel-coreos-9 (Red Hat OpenShift Container Platform 4) - Fix deferred
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-82720 unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup [fedora-all]
bugzilla·2026-09-21·CVSS 5.9
CVE-2026-82720 [MEDIUM] CVE-2026-82720 unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup [fedora-all]
CVE-2026-82720 unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If the prerequisites are satisfied (possible RPZ drop or
Bugzilla
CVE-2026-82720 unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup
bugzilla·2026-09-16·CVSS 5.9
CVE-2026-82720 [MEDIUM] CVE-2026-82720 unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup
CVE-2026-82720 unbound: Unbound: Denial of Service via use-after-free in DoH stream cleanup
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If the prerequisites are satisfied (possible RPZ drop or heavy client traffic), a malicious actor can trigger the vulnerability with a single DoH connection and the appropriate traffic. Impact is limited as the reads are not user controlled and the use-after-free leads to early returns. However
Hackernews
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
blogs_hackernews·2026-09-17·CVSS 9.8
CVE-2026-81642 [CRITICAL] Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws. One of the eight, CVE-2026-82717 , is a heap corruption bug in CNAME synthesis reported by Ben Morris of Anthropic. It could also lead to remote code
2026-09-16
Published