{
  "id": 11811181,
  "title": "I Traced Unbound's DNSSEC Heap Overflow: 4 Checks to Run",
  "url": "https://urgent.news/2026/10/04/i-traced-unbounds-dnssec-heap-overflow-4-checks-to-run",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-04T01:12:46.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kielltampubolon/i-traced-unbounds-dnssec-heap-overflow-4-checks-to-run-1ejh"
  },
  "original_language": "en",
  "account": "CVE-2026-81642 and CVE-2026-86003 are two critical vulnerabilities affecting Unbound and CoreDNS respectively. The Unbound vulnerability is a heap overflow in the DNSSEC validator caused by a compression pointer within a DNSKEY record that points back to itself. This allows an attacker to cause remote code execution through attacker-controlled data. Similarly, the CoreDNS vulnerability arises from unauthenticated DNS UPDATEs being accepted over encrypted transports, allowing an attacker to exploit the trusted middleman role and potentially take over names. Both issues affect all releases up to 1.26.0, with Unbound patched in 1.26.1 and CoreDNS in 1.14.7. The primary risk comes from users unknowingly querying malicious domains through compromised links, as no public exploit has been discovered. To mitigate these threats, it is crucial to verify the exact versions of Unbound and CoreDNS running on resolver hosts, conduct a comprehensive inventory of resolvers within the network, and promptly apply the respective patches.",
  "summary": "[ attacker's zone ] ──► ┌────────────────────────────┐ │ Unbound (recursive, DNSSEC)│ │ CVE-2026-81642 CWE-122 │ │ DNSKEY -> digest buffer │ └────────────────────────────┘ A compression pointer inside a DNSSEC key record can overflow a heap buffer in the most security-conscious component of your resolver stack, and the vendor's own advisory says remote code execution is possible through attacker…",
  "key_points": [
    "Unbound has heap overflow in DNSSEC validator",
    "CoreDNS accepts unauthenticated DNS UPDATEs over encrypted transport",
    "Both vulnerabilities affect all releases up to 1.26.0"
  ],
  "editors_take": "This development heightens the urgency for organizations to verify and update their Unbound and CoreDNS versions to prevent potential remote code execution through malicious domain queries.",
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}