Heap Memory Corruption in NLnet Labs Unbound by NLnet Labs
CVE-2026-82717

8.4HIGH

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2026-82717?

A vulnerability in NLnet Labs Unbound versions up to and including 1.26.0 allows for heap memory corruption that may lead to remote code execution. This issue arises during the CNAME synthesis process when handling upstream responses, particularly when enforcing a maximum TTL value in the packet buffer. The vulnerability exploits a compression pointer that may be directed toward an overwritten value, leading to an improper buffer position adjustment. Consequently, this can result in memory corruption, crashes, and potential remote code execution on specific systems and under certain compilation options.

Affected Version(s)

Unbound 0 < 1.26.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ben Morris (Anthropic)
.