Use-after-free in Unbound - CVE-2026-33278
Published: May 20, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service and potentially execute arbitrary code.
The vulnerability exists due to use-after-free in Unbound DNSSEC validator when processing validation state for DS sub-queries after deep-copying response messages during NSEC3 computational budget exhaustion. A remote attacker can control a malicious signed zone and query a vulnerable resolver to cause a denial of service and potentially execute arbitrary code.
Exploitation requires control of a malicious signed zone.