๐Ÿ” CVE Alert

CVE-2026-81634

HIGH 7.5

Possible heap buffer overflow during DNSSEC canonicalization

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

In NLnet Labs Unbound up to and including 1.26.0, a 255 length query name with a large TCP response can lead to a heap buffer overflow during the RRSet canonicalisation routine. This is caused by missing to add the first owner name into the buffer length check. A malicious actor operating a malicious name server or tampering with an incoming response to Unbound (canonicalisation happens before DNSSEC validation), can trigger the vulnerability.

CWE CWE-122
Vendor nlnet labs
Product unbound
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for nlnet labs unbound

Be the first to know when new high vulnerabilities affecting nlnet labs unbound are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

NLnet Labs / Unbound
0 < 1.26.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
nlnetlabs.nl: https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-81634.txt

Credits

Vlatko Kosturjak (Marlink Cyber)