CRITICAL 9.1 NVD

CVE-2026-81642

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code exec

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.

References

Published: 2026-09-16 · Source: NVD · Feed updated: 2026-09-16
This critical severity vulnerability with a CVSS score of 9.1 was published on 2026-09-16 via NVD.

Risk Timeline

CVE Disclosed2026-09-16 · -1 days ago

Remediation Resources

vulnfeed aggregates 14391 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.