NLnet Labs has addressed multiple vulnerabilities in the Unbound DNS resolver, including CVE-2026-33278, a high-severity flaw in the DNSSEC validator that can cause denial of service and potentially remote code execution. The bug affects Unbound versions 1.19.1 through 1.25.0 and stems from a deep-copy error that overwrites a destination pointer, later triggering a dangling-pointer dereference. The issue is tracked under CWE-416 and CWE-672 and carries high potential impact to confidentiality, integrity, and availability.
Exploitation requires an attacker to control a malicious signed DNS zone and induce a vulnerable Unbound instance to query it while a DS sub-query is suspended because of NSEC3 computational budget exhaustion. Belgium's Centre for Cybersecurity warned that the Unbound vulnerabilities could enable denial-of-service and urged organizations to patch immediately. The vendor has fixed the issue in Unbound 1.25.1, making upgrade a priority for operators using affected resolver versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Belgium's Centre for Cybersecurity issued an advisory warning that NLnet Labs had addressed multiple vulnerabilities in the Unbound DNS resolver and urged immediate patching. The advisory indicates broader official dissemination of the fixes beyond the initial vulnerability disclosure.
CVE-2026-33278 was publicly disclosed as a newly received vulnerability affecting the Unbound DNS resolver. Public details described possible denial of service and potential arbitrary code execution during DNSSEC validation.
NLnet Labs addressed CVE-2026-33278 in Unbound version 1.25.1. The issue affects Unbound versions 1.19.1 through 1.25.0 and requires a malicious signed zone plus a query during DS sub-query suspension triggered by NSEC3 computational budget exhaustion.
The vulnerability later assigned CVE-2026-33278 was introduced in NLnet Labs Unbound version 1.19.1. The flaw stems from a deep-copy bug in the DNSSEC validator that can cause a dangling-pointer dereference, enabling denial of service and potentially remote code execution under specific conditions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourceccb.belgium.be
Open sourcecvefeed.io
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.