Build1 publisher2 min readPublished
Unbound 1.26.1 fixes a DNSSEC heap overflow its vendor says could allow remote code execution
NLnet Labs' Unbound 1.26.1 fixes CVE-2026-81642, a DNSSEC heap overflow its vendor says could allow remote code execution. A related CoreDNS flaw in its newer transport listeners gives resolver operators a second check, this one in their configuration.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- A DNSKEY record whose owner name uses a compression pointer into its own RDATA overflows the digest buffer Unbound uses while validating.
- Every Unbound release through 1.26.0 is affected, and the 1.26.1 fix shipped as a security release on September 16.
- When the post was written there was no public exploit and no KEV listing, and CISA's SSVC assessment rated exploitation as none.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision One upgrade to Unbound 1.26.1 retires five advisories, so the version string settles the whole batch and a separate mitigation for CVE-2026-81642 buys nothing.
- exposure Any client who follows a link to an attacker's domain can make the recursive resolver fetch the hostile zone, so every user it serves can trigger the bug without credentials.
- cost Operators who enabled DoH, DoQ, HTTP/3 or gRPC on CoreDNS inherited the unfiltered path, and safe operation of those listeners now depends on every upstream's UPDATE policy.
The DNS wire format permits compression pointers. Their job is to save space when the same name appears more than once in a message [14]. According to the dev.to post that traced CVE-2026-81642, Unbound expands those pointers while it builds the digest of a DNSKEY RRset [12]. A pointer that lands back inside the same record's data creates a cycle, and the code filling the digest buffer kept writing with no bound check on that path [12]. "The validator, it turns out, did not expect a key record to point at itself," the author wrote [1]. The author built that account from the NLnet Labs advisory and the CWE-122 heap overflow classification, and has not reproduced it in a lab [11] [7].
NLnet Labs' advisory says remote code execution is possible through attacker controlled data [2]. "Possible, not demonstrated," the author wrote [2]. The attacker needs a zone they control and a resolver willing to query it [6].
Triage on Unbound starts with `unbound -V | head -n 1`. For a containerised resolver, run the same command through `docker exec` [13]. The author argues that the way the bug works explains why checking the version beats generic hardening here [16].
CoreDNS is the better design lesson. The default message-acceptance function filters unusual message types. Each listener has to apply it, and only the UDP, TCP and DoT listeners do [8]. The post frames the flaw as encrypted versus plaintext. But DoT is encrypted, and it is on the filtered side [8]. The real split is between the original listeners and the newer DoH, DoQ, HTTP/3 and gRPC listeners, which call the unpack routine directly [8]. Four of seven transports therefore accept a DNS UPDATE from an unauthenticated client that the other three would drop [2] [9]. Each listener had to call the check itself, so every transport added later had to remember it, and four did not [2].
The impact depends on the setup. The CoreDNS advisory lists name takeover as an outcome only where an upstream trusts CoreDNS's connection and accepts updates without end-to-end TSIG [10]. The post does not give a fixed CoreDNS release [15]. Until one is confirmed, the check is in the configuration. Find out which of the four unfiltered listeners are enabled, and whether each upstream that accepts UPDATE requires TSIG [8] [10].
What to watch
- A public exploit, a KEV listing, or a change in CISA's SSVC exploitation rating for CVE-2026-81642 would move remote code execution from possible to demonstrated.
- A CoreDNS release that applies the message-acceptance filter to DoH, DoQ, HTTP/3 and gRPC, and whether it moves the check into the shared unpack path.
- NLnet Labs' detail on CVE-2026-81634 and CVE-2026-82717, the two HIGH issues bundled into Unbound 1.26.1.