SecurityUnverified

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with

What happened

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution. Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with

Why it matters

The launch may affect adoption and competitive positioning for Security; usage evidence is the next signal to watch.

Affected entities

View evidence

1 reports · 1 original report · 1 independent

  1. The Hacker NewsPrimary source · Supports · EN · 100%
    Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Claims

  • Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone Reported

Conflicts

No material conflict detected in the available evidence.

Timeline

  1. First reported

Market move following event

Market reaction is not yet available for this asset and time window.

Score explanation

Confidence · formula confidence-2.1.0
Source trust80
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude69
Market relevance74
Entity significance42
Market breadth45
Novelty68
Urgency62
Ranking · formula rank-1.0.0
Confidence factor0.748
Freshness factor0.9853
Breaking bonus0