---
id: CVE-2026-81642
title: >-
  In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in
  the DNSSEC validator that enables denial of service and possible remote code
  execution as a result of digesting DNSKEYs
summary: >-
  In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in
  the DNSSEC validator that enables denial of service and possible remote code
  execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression
  po…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
vendor: nlnetlabs
product: unbound
affected:
  - unbound < 1.26.1
patched:
  - unbound 1.26.1
published: '2026-09-16'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T18:59:21.953'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81642'
references:
  - url: 'https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-81642.txt'
    label: sep@nlnetlabs.nl
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81642.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-81642'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2535059'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-81642'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81642'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68590'
  - url: 'https://access.redhat.com/errata/RHSA-2026:70754'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71459'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71419'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71610'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71611'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71460'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71487'
  - url: 'https://access.redhat.com/errata/RHSA-2026:72183'
  - url: 'https://access.redhat.com/errata/RHSA-2026:72110'
tags:
  - nvd
  - exploit-available
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00962
epssPercentile: 0.6003
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/suominen/CVE-2026-81642'
  checkedAt: '2026-09-26T09:06:01.793Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-09-16T14:30:20.298477Z'
scores:
  nvd: 9.8
  cna: 9.1
  vendor: 9.8
ingestedAt: '2026-09-16T08:52:29.598Z'
---

## Overview

In NLnet Labs Unbound up to and including 1.26.0, a vulnerability was found in the DNSSEC validator that enables denial of service and possible remote code execution as a result of digesting DNSKEYs. A DNSKEY with an owner compression pointer to its own RDATA can overflow the digest buffer. Remote code execution is possible through attacker controlled data. An adversary can exploit the vulnerability by controlling a malicious zone and querying a vulnerable Unbound.

## Affected

- `unbound < 1.26.1`

## Remediation

Upgrade past the affected range:

- `unbound 1.26.1`

## Vendor advisories

- **Red Hat VEX** · Critical · affected: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7 · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-81642.json)
- **RHSA-2026:68590** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68590)
- **RHSA-2026:70754** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:70754)
- **RHSA-2026:71459** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71459)
- **RHSA-2026:71419** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71419)
- **RHSA-2026:71610** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71610)
- **RHSA-2026:71611** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71611)
- **RHSA-2026:71460** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71460)
- **RHSA-2026:71487** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71487)
- **RHSA-2026:72183** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-09-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:72183)
- **RHSA-2026:72110** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-09-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:72110)
