Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws.
It could also lead to remote code execution "under certain systems and compilation options," NLnet Labs said.
The Critical validator bug NLnet Labs fixed in May, CVE-2026-33278 , is a different flaw, and the 1.25.1 update that fixed it does not fix this one.
Debian's security tracker listed unbound 1.26.1-1 as fixed in unstable on Thursday, with the bookworm, trixie, and forky branches still listed as vulnerable.
Unbound 1.26.1 is available as source, with checksums and a PGP signature, and as Windows installers and binaries.
The ReTrap fix also changes a default: val-clean-more is now off, so Unbound no longer validates DNSSEC data in the more section of a response by default.
What happened
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642 , along with eight other flaws.
Who is affected
It could also lead to remote code execution "under certain systems and compilation options," NLnet Labs said.
Technical details
The Critical validator bug NLnet Labs fixed in May, CVE-2026-33278 , is a different flaw, and the 1.25.1 update that fixed it does not fix this one.
Debian's security tracker listed unbound 1.26.1-1 as fixed in unstable on Thursday, with the bookworm, trixie, and forky branches still listed as vulnerable.
Response
Unbound 1.26.1 is available as source, with checksums and a PGP signature, and as Windows installers and binaries.
The ReTrap fix also changes a default: val-clean-more is now off, so Unbound no longer validates DNSSEC data in the more section of a response by default.
What remains unknown
NLnet Labs attaches no configuration condition to that range, and it has not said whether a resolver with DNSSEC validation switched off is reachable.
Attribution
The Hacker News: Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
What to watch next
Watch for revised vendor guidance, fixed versions and mitigation updates.