{
  "schemaVersion": "guard-threat-campaign/v1",
  "id": "HGTC-2026-8F7CDB8E",
  "slug": "cve-2026-81642-unbound-dnskey-digest-rce",
  "title": "Unbound DNSKEY digest overflow can RCE resolvers",
  "aliases": [
    "CVE-2026-81642",
    "Unbound DNSKEY RCE"
  ],
  "summary": "NLnet Labs Unbound through 1.26.0 can overflow a digest buffer while validating a malicious DNSKEY (owner compression pointer into its own RDATA), enabling DoS and possible remote code execution when the resolver digests attacker-controlled zone data. Upgrade to Unbound 1.26.1 or later.",
  "status": "published",
  "severity": "critical",
  "confidence": "high",
  "uncertainty": "Remote code execution requires attacker-controlled zone data reaching the validator; packaging lag means distro packages may still ship 1.26.0 until rebuilds land.",
  "firstObservedAt": "2026-09-16T08:43:17.995Z",
  "lastObservedAt": "2026-09-16T12:00:00.000Z",
  "publishedAt": "2026-09-20T13:02:24.592Z",
  "reviewedAt": "2026-09-20T13:02:09.832Z",
  "expiresAt": "2026-09-16T12:00:00.000Z",
  "reviewer": "HOL Guard Security Publishing",
  "sources": [
    {
      "id": "nlnetlabs-81642",
      "label": "NLnet Labs Unbound CVE-2026-81642 advisory",
      "url": "https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-81642.txt",
      "sourceType": "vendor_advisory",
      "observedAt": "2026-09-16T00:00:00.000Z"
    },
    {
      "id": "hol-blog-81642",
      "label": "HOL Guard operator write-up",
      "url": "https://hol.org/blog/cve-2026-81642-unbound-dnskey-digest-rce",
      "sourceType": "other_primary",
      "observedAt": "2026-09-16T12:00:00.000Z"
    }
  ],
  "artifacts": [
    {
      "id": "unbound",
      "artifactClass": "package",
      "ecosystem": "native",
      "name": "unbound",
      "version": "<=1.26.0",
      "defanged": false
    }
  ],
  "indicators": [],
  "timeline": [
    {
      "id": "disclosure",
      "occurredAt": "2026-09-16T08:43:17.995Z",
      "eventType": "disclosure",
      "summary": "NLnet Labs published CVE-2026-81642 for Unbound DNSKEY digest buffer overflow.",
      "sourceIds": [
        "nlnetlabs-81642"
      ]
    },
    {
      "id": "vendor-fix",
      "occurredAt": "2026-09-16T00:00:00.000Z",
      "eventType": "vendor_action",
      "summary": "Fixed in Unbound 1.26.1 per vendor advisory.",
      "sourceIds": [
        "nlnetlabs-81642"
      ]
    },
    {
      "id": "hol-publish",
      "occurredAt": "2026-09-16T12:00:00.000Z",
      "eventType": "other",
      "summary": "HOL Guard published operator blog and social coverage for CVE-2026-81642.",
      "sourceIds": [
        "hol-blog-81642"
      ]
    }
  ],
  "coverage": [],
  "policies": [],
  "limitations": [
    "Only validating Unbound instances that process attacker-influenced DNSKEYs are in scope.",
    "OS package rebuilds may lag the upstream 1.26.1 tag.",
    "This campaign does not cover unrelated Unbound CVEs in the same release train."
  ],
  "correctionHref": "/guard/security/campaigns/cve-2026-81642-unbound-dnskey-digest-rce/corrections"
}
