Heap-based buffer overflow in Unbound - CVE-2026-42944
Published: May 20, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in the EDNS option encoder when processing queries containing multiple NSID and/or DNS Cookie EDNS and/or EDNS Padding options. A remote attacker can send a specially crafted query to cause a denial of service.
Only instances with the relevant EDNS options enabled are vulnerable.