← All articles

Critical Unbound DNS flaw allows code execution through a malicious zone

NLnet Labs patched a critical heap overflow in the DNSSEC validator of Unbound, one of the most widely used recursive DNS resolvers. Tracked as CVE-2026-81642, the flaw can be triggered when a resolver queries a zone an attacker controls, and it can lead to remote code execution. The bug lies in how the validator parses a signing-key record whose owner name points back into the record's own data. Every Unbound release up to and including 1.26.0 is affected, and the fix is in 1.26.1, which also addresses eight other flaws, including a second that could allow code execution. No exploitation is reported, but resolvers query attacker-controlled zones during normal operation.

Check
Update Unbound to 1.26.1 across recursive resolvers, including any bundled in appliances or home-network setups, and if you cannot upgrade immediately, apply the vendor's source patches or temporarily disable DNSSEC validation.
Affected
Anyone running Unbound 1.26.0 or earlier as a recursive DNS resolver (CVE-2026-81642); querying an attacker-controlled zone can trigger a heap overflow with possible remote code execution, and normal resolution reaches such zones.
Fix
Patch to 1.26.1, apply the standalone source patches if you cannot upgrade, treat DNS resolvers as exposed infrastructure since they process untrusted data, and monitor resolvers for crashes and unexpected behavior.