← Back to CVE List
Vulnerability Intelligence Report
Possible arbitrary code execution during DNSSEC validation

CVE-2026-33278

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.

No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
EPSS Probability:1.27%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-416 ↗CWE-416: Use After Free
CWE-672 ↗CWE-672: Operation on a Resource after Expiration or Release

Affected Products & Versions

Vendor Product Affected Versions
NLnet Labs Unbound 1.19.1 < 1.25.1 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
1.272%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityNLnet Labs
Reserved2026-05-07T10:07:51
Published2026-05-20T09:18:15
Patch Date2026-05-20
Last Updated2026-09-01T12:04:59

LINK COPIED TO CLIPBOARD