Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Medium Severity
Global
Date OccurredSep 17, 202612:30 UTC
Event TypeCyber Intelligence
SourceTheHackerNews
RecordedSep 17, 2026
Full Description
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who control