CVE-2026-33278Patch(nlnetlabs / unbound)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nlnetlabs unbound systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416CWE-672

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • unbound

Threat summary

  • Patch or workaround signal is available
  • 15 mentions across 6 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 5 mentions (2026-05-20); latest day: 1
  • 15 total mentions across 6 days

Affected systems

Vendors
Products
unbound

Deep dive

Activity timeline15 mentions / 6d
01345Mentions · 2026-05-20: 5Mentions · 2026-05-21: 5Mentions · 2026-05-25: 2Mentions · 2026-05-26: 1Mentions · 2026-06-01: 1Mentions · 2026-08-06: 1Patch / Workaround · 2026-05-20: 4Patch / Workaround · 2026-05-21: 4Patch / Workaround · 2026-05-26: 1Patch / Workaround · 2026-08-06: 1Technical Details · 2026-05-20: 4Technical Details · 2026-05-21: 2Technical Details · 2026-05-26: 105-2005-2105-2505-2606-0108-06
Signal classification3 categories
Patch
1066.7%
Disclosure
426.7%
General
16.7%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-05-205
Disclosure1Patch4
2026-05-215
General1Patch4
2026-05-252
Disclosure2
2026-05-261
Patch1
2026-06-011
Disclosure1
2026-08-061
Patch1
Full discourse15 posts
  • Yasuhiro Morishita@OrangeMorishita
    Disclosure

    【自分用メモ】CVE-2026-33278。UnboundのRCE脆弱性。CVSSスコア9.1。エグい。 https://nlnetlabs.nl/downloads/unbound/CVE-2026-33278.txt CVE Record: CVE-2026-33278 https://www.cve.org/CVERecord?id=CVE-2026-33278

    Post summary

    The memo records CVE‑2026‑33278 as an RCE flaw in Unbound with a CVSS score of 9.1, providing links to further details.

    01011662.2K
    4.5K followersView on X
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【注意喚起】Unboundの脆弱性情報が公開されました(CVE-2026-33278、他10件) https://jprs.jp/tech/security/2026-05-25-unbound.html

    Post summary

    The message announces that vulnerability information for Unbound, including CVE-2026-33278 and nine other CVEs, has been published, and provides a link to the full report.

    0842003.4K
    1.3K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    Unbound 1.25.1 fixes 11 CVEs https://www.openwall.com/lists/oss-security/2026/05/20/5 CVE-2026-33278: Remote code execution during DNSSEC validation CVE-2026-42944: Heap overflow and crash with multiple nsid, cookie, padding EDNS options CVE-2026-42959: Crash during DNSSEC validation of malicious content +8 more

    Post summary

    The notice announces that Unbound version 1.25.1 includes fixes for 11 CVEs, including remote code execution and heap overflow issues affecting DNSSEC validation, thereby providing a patch to mitigate these vulnerabilities.

    0601641.8K
    4.7K followersView on X
  • Mahdi Akrami 🏴@MahdiAkrami01
    Patch

    🚨آسیپ پذیری جدید برای cPanel/WHM ورژن 126 یا بالاتر ظاهرا یه سوراخی تو unbound پیدا شده سریع تر آپدیت کنید (با ذکر ریدم تو دهنت فیلترچی) CVE-2026-33278 https://support.cpanel.net/hc/en-us/articles/40646746647703-Security-CVE-2026-33278-cpanel-unbound-1-25-1-Security-Release-May-21-2026

    Post summary

    A new CVE-2026-33278 affecting cPanel/WHM version 126+ (unbound) has been disclosed; a security release is available and users are urged to update promptly.

    1001731.4K
    1.3K followersView on X
  • mailcow@mailcow_email
    Patch

    Release 2026-05c is here! https://mailcow.email/posts/2026/release-2026-05/ This update fixes CVE-2026-33278 in unbound and bumps Nginx to version 1.30.2. We strongly recommend updating to this version.

    Post summary

    The release notes announce an update that patches CVE-2026-33278 in unbound and upgrade Nginx, with a recommendation to update.

    0001501.2K
    1.7K followersView on X
  • 日本レジストリサービス(JPRS)@JPRS_official
    Disclosure

    【メールマガジン(FROM JPRS)】バックナンバーを更新しました。 通常号 vol.1247「Unboundの脆弱性情報が公開されました(CVE-2026-33278、他10件)、他1件」など https://jprs.jp/mail/backnumber/2026/260601.html

    Post summary

    The JPRS newsletter announces the release of vulnerability information for CVE-2026-33278 (Unbound) and 10 other items, but no PoC, exploit, patch, or active exploitation details are provided.

    00031312
    1.3K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Patch

    ・Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42959, Crash during DNSSEC validation of malicious content. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks to Andrew Griffiths from ‘http://calif.io’ for the report. ・Fix CVE-2026-40622, “Ghost domain name” variant. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-41292, Parsing a long list of incoming EDNS options degrades performance. Thanks to GitHub user ‘N0zoM1z0’, also Qifan Zhang from Palo Alto Networks, for the report. ・Fix CVE-2026-42534, Jostle logic bypass degrades resolution performance. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42923, Degradation of service with unbounded NSEC3 hash calculations. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-42960, Possible cache poisoning attack while following delegation. Thanks to TaoFei Guo from Peking University, Yang Luo and JianJun Chen, Tsinghua University, for the report. ・Fix CVE-2026-44390, Unbounded name compression in certain cases causes degradation of service. Thanks to Qifan Zhang, Palo Alto Networks, for the report. ・Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks to Qifan Zhang, Palo Alto Networks, for the report.

    Post summary

    The post announces that multiple CVEs have been fixed, provides concise technical details for each, credits researchers, and indicates that patches are available, with no evidence of PoC, exploit, or active use.

    11010442
    4.5K followersView on X
  • strnh@strnh
    Patch

    https://ubuntu.com/security/CVE-2026-33278 個人的には unbound を git でソースから拾ってコンパイルして入れるほうがベンダー・パッチよりは無駄がないと思うのだが、ロック・インしたいポリシがあるところに逆らえない方々は苦労するよな。

    Post summary

    The author recommends compiling unbound from source rather than applying the vendor patch for CVE‑2026‑33278, noting that lock‑in policy constraints could pose challenges.

    00010114
    1.9K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #NLnet Labs has addressed multiple vulnerabilities, #CVE-2026-33278; #CVE-2026-42944; #CVE-2026-42959. Successful exploitation could enable to denial of service #DoS, and potentially remote code execution #RCE! #Patch #Patch #Patch

    Post summary

    NLnet Labs has released patches for CVE‑2026‑33278, CVE‑2026‑42944 and CVE‑2026‑42959, which could lead to DoS or RCE if exploited.

    01000182
    7.2K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-42945 2 - CVE-2026-46333 3 - CVE-2026-0265 4 - CVE-2020-2033 5 - CVE-2026-33278 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    A simple announcement of the top five trending CVEs, with no further technical or operational details provided.

    00010203
    1.7K followersView on X
  • Yasuhiro Morishita@OrangeMorishita
    Patch

    "This release consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608."

    Post summary

    This release consolidates fixes for a series of CVEs, signaling patch availability without providing exploit, PoC, or detailed vulnerability information.

    10000228
    4.5K followersView on X
  • ohhara_P🧐Slow life in the isekai@ohhara_shiojiri
    Disclosure

    Unboundの脆弱性情報が公開されました(CVE-2026-33278、他10件) https://jprs.jp/tech/security/2026-05-25-unbound.html

    Post summary

    An article announcing Unbound vulnerabilities, including CVE‑2026‑33278, has been published, but no additional details about exploitation or mitigation are provided.

    0000082
    2.0K followersView on X
  • Fusioned@fusionednet
    Patch

    All managed Cloud/Dedicated servers have been updated to #cPanel 11.134.0.30 following the CVE-2026-33278 cpanel-unbound 1.25.1 Security Release. https://support.cpanel.net/hc/en-us/articles/40646746647703-Security-CVE-2026-33278-cpanel-unbound-1-25-1-Security-Release-May-21-2026

    Post summary

    The post announces that cloud/dedicated servers were updated to patch CVE-2026-33278 and links to a cPanel security release article.

    0000081
    246 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🔐 NLnet Labs released Unbound 1.25.1 with fixes for 11 CVEs — including a use-after-free in the DNSSEC validator (CVE-2026-33278) that could lead to remote code execution, and a cache poisoning flaw (CVE-2026-42960). 🔗 https://threataft.com/articles/unbound-1-25-1-11-cves-dnssec-rce-cache-poisoning #CyberSecurity #ThreatIntel #DNS

    Post summary

    NLnet Labs has released Unbound 1.25.1, fixing 11 CVEs including a use‑after‑free that could cause RCE and a cache poisoning flaw; the post confirms a patch is available but no PoC, exploit, or active exploitation is reported.

    0000093
    26 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: Ubuntu fixes 5 Unbound flaws including CVE-2026-32792 and CVE-2026-33278 affecting 22.04, 24.04, 25.10, 26.04 LTS with DoS and RCE risk, urges immediate updates. https://threatcluster.io/cluster/multiple-unbound-vulnerabilities-in-ubuntu-lead-to-dos-and-r-b8dadf0b

    Post summary

    Ubuntu has fixed five Unbound vulnerabilities, including CVE-2026-32792 and CVE-2026-33278, which pose DoS and RCE risks; the advisement urges users to apply updates immediately.

    0000089
    274 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnlnetlabsunbound---

Explore more