Denial of Service and Remote Code Execution in NLnet Labs Unbound DNS Resolver
CVE-2026-33278

9.1CRITICAL

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
20 May 2026

What is CVE-2026-33278?

A vulnerability in NLnet Labs' Unbound DNS resolver has been identified in versions 1.19.1 through 1.25.0, affecting the DNSSEC validator. The issue arises when the DNSSEC validator attempts to handle deep copying of data structures. An attacker could exploit this flaw by crafting a malicious signed zone and querying a vulnerable instance of Unbound. The vulnerability allows for Denial of Service due to pointer mishandling that can lead to dereferencing a dangling pointer after memory regions have been freed. The potential outcome includes application crashes or arbitrary code execution if the exploit is successfully executed. A patch addressing the issue has been implemented in Unbound version 1.25.1.

Affected Version(s)

Unbound 1.19.1 < 1.25.1

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.