Signal is active with 1 mentions in latest observed window
Immediate actions
Patch nlnetlabs unbound systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.
The message announces that vulnerability information for Unbound, including CVE-2026-33278 and nine other CVEs, has been published, and provides a link to the full report.
Unbound 1.25.1 fixes 11 CVEs https://www.openwall.com/lists/oss-security/2026/05/20/5
CVE-2026-33278: Remote code execution during DNSSEC validation
CVE-2026-42944: Heap overflow and crash with multiple nsid, cookie, padding EDNS options
CVE-2026-42959: Crash during DNSSEC validation of malicious content
+8 more
Post summary
The notice announces that Unbound version 1.25.1 includes fixes for 11 CVEs, including remote code execution and heap overflow issues affecting DNSSEC validation, thereby providing a patch to mitigate these vulnerabilities.
🚨آسیپ پذیری جدید برای cPanel/WHM ورژن 126 یا بالاتر
ظاهرا یه سوراخی تو unbound پیدا شده
سریع تر آپدیت کنید (با ذکر ریدم تو دهنت فیلترچی)
CVE-2026-33278
https://support.cpanel.net/hc/en-us/articles/40646746647703-Security-CVE-2026-33278-cpanel-unbound-1-25-1-Security-Release-May-21-2026
Post summary
A new CVE-2026-33278 affecting cPanel/WHM version 126+ (unbound) has been disclosed; a security release is available and users are urged to update promptly.
Release 2026-05c is here!
https://mailcow.email/posts/2026/release-2026-05/
This update fixes CVE-2026-33278 in unbound and bumps Nginx to version 1.30.2.
We strongly recommend updating to this version.
Post summary
The release notes announce an update that patches CVE-2026-33278 in unbound and upgrade Nginx, with a recommendation to update.
The JPRS newsletter announces the release of vulnerability information for CVE-2026-33278 (Unbound) and 10 other items, but no PoC, exploit, patch, or active exploitation details are provided.
・Fix CVE-2026-33278, Possible remote code execution during DNSSEC validation. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
・Fix CVE-2026-42944, Heap overflow and crash with multiple nsid, cookie, padding EDNS options. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
・Fix CVE-2026-42959, Crash during DNSSEC validation of malicious content. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
・Fix CVE-2026-32792, Packet of death with DNSCrypt. Thanks to Andrew Griffiths from ‘http://calif.io’ for the report.
・Fix CVE-2026-40622, “Ghost domain name” variant. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
・Fix CVE-2026-41292, Parsing a long list of incoming EDNS options degrades performance. Thanks to GitHub user ‘N0zoM1z0’, also Qifan Zhang from Palo Alto Networks, for the report.
・Fix CVE-2026-42534, Jostle logic bypass degrades resolution performance. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
・Fix CVE-2026-42923, Degradation of service with unbounded NSEC3 hash calculations. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
・Fix CVE-2026-42960, Possible cache poisoning attack while following delegation. Thanks to TaoFei Guo from Peking University, Yang Luo and JianJun Chen, Tsinghua University, for the report.
・Fix CVE-2026-44390, Unbounded name compression in certain cases causes degradation of service. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
・Fix CVE-2026-44608, Use after free and crash in RPZ code. Thanks to Qifan Zhang, Palo Alto Networks, for the report.
Post summary
The post announces that multiple CVEs have been fixed, provides concise technical details for each, credits researchers, and indicates that patches are available, with no evidence of PoC, exploit, or active use.
The author recommends compiling unbound from source rather than applying the vendor patch for CVE‑2026‑33278, noting that lock‑in policy constraints could pose challenges.
Warning: #NLnet Labs has addressed multiple vulnerabilities, #CVE-2026-33278; #CVE-2026-42944; #CVE-2026-42959. Successful exploitation could enable to denial of service #DoS, and potentially remote code execution #RCE! #Patch#Patch#Patch
Post summary
NLnet Labs has released patches for CVE‑2026‑33278, CVE‑2026‑42944 and CVE‑2026‑42959, which could lead to DoS or RCE if exploited.
"This release consolidates security fixes for issues reported over a period of time. There are fixes for CVE-2026-33278, CVE-2026-42944, CVE-2026-42959, CVE-2026-32792, CVE-2026-40622, CVE-2026-41292, CVE-2026-42534, CVE-2026-42923, CVE-2026-42960, CVE-2026-44390 and CVE-2026-44608."
Post summary
This release consolidates fixes for a series of CVEs, signaling patch availability without providing exploit, PoC, or detailed vulnerability information.
An article announcing Unbound vulnerabilities, including CVE‑2026‑33278, has been published, but no additional details about exploitation or mitigation are provided.
All managed Cloud/Dedicated servers have been updated to #cPanel 11.134.0.30 following the CVE-2026-33278 cpanel-unbound 1.25.1 Security Release.
https://support.cpanel.net/hc/en-us/articles/40646746647703-Security-CVE-2026-33278-cpanel-unbound-1-25-1-Security-Release-May-21-2026
Post summary
The post announces that cloud/dedicated servers were updated to patch CVE-2026-33278 and links to a cPanel security release article.
🔐 NLnet Labs released Unbound 1.25.1 with fixes for 11 CVEs — including a use-after-free in the DNSSEC validator (CVE-2026-33278) that could lead to remote code execution, and a cache poisoning flaw (CVE-2026-42960).
🔗 https://threataft.com/articles/unbound-1-25-1-11-cves-dnssec-rce-cache-poisoning
#CyberSecurity#ThreatIntel#DNS
Post summary
NLnet Labs has released Unbound 1.25.1, fixing 11 CVEs including a use‑after‑free that could cause RCE and a cache poisoning flaw; the post confirms a patch is available but no PoC, exploit, or active exploitation is reported.
BREAKING: Ubuntu fixes 5 Unbound flaws including CVE-2026-32792 and CVE-2026-33278 affecting 22.04, 24.04, 25.10, 26.04 LTS with DoS and RCE risk, urges immediate updates.
https://threatcluster.io/cluster/multiple-unbound-vulnerabilities-in-ubuntu-lead-to-dos-and-r-b8dadf0b
Post summary
Ubuntu has fixed five Unbound vulnerabilities, including CVE-2026-32792 and CVE-2026-33278, which pose DoS and RCE risks; the advisement urges users to apply updates immediately.