Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-33278

43
FAUCET Score

NLnet Labs Unbound 1.19.1 up to and including version 1.25.0 has a vulnerability in the DNSSEC validator that enables denial of service and possible remote code execution as a result of deep copying a data structure and erroneously overwriting a destination pointer. An adversary can exploit the vulnerability by controlling a malicious signed zone and querying a vulnerable Unbound. When DS sub-queries need to suspend validation due to NSEC3 computational budget exhaustion (introduced in Unbound 1.19.1), Unbound deep-copies response messages to preserve them across memory region teardown. A struct-assignment bug overwrites the destination's pointer with the source's pointer. After the sub-query region is freed, the resumed validator dereferences this dangling pointer, triggering a crash or potentially enabling arbitrary code execution. Unbound 1.25.1 contains a patch with a fix to preserve the correct pointer when deep copying the data structure.

First published: May 20, 2026Last modified: May 20, 2026

Impacted Technologies

VendorProductVersion(s)CPE
>= 1.19.1, < 1.25.1CPE matchmatch criteria
cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

9.1CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:Red

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
UNREPORTED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
1.27%
Probability of exploitation in next 30 days
EPSS Percentile
66.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0127 is in the 53rd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: azl3 unbound 1.19.1-5 on Azure Linux 3.0Fixed in: 1.25.1-1
microsoftpatch availablevia msrc
Product: 20736-17084Fixed in: 1.25.1-1
ubuntupatch availablevia ubuntu_usn
Product: unbound (jammy)Fixed in: 1.13.1-1ubuntu5.15
ubuntupatch availablevia ubuntu_usn
Product: unbound (noble)Fixed in: 1.19.2-1ubuntu3.8
ubuntupatch availablevia ubuntu_usn
Product: unbound (questing)Fixed in: 1.22.0-2ubuntu2.3
ubuntupatch availablevia ubuntu_usn
Product: unbound (resolute)Fixed in: 1.24.2-1ubuntu2.1

Vendor Advisories (2)

ubuntuUSN-8282-1

Unbound vulnerabilities

May 20, 2026
microsoft2026-May/CVE-2026-33278Critical

Possible arbitrary code execution during DNSSEC validation

May 12, 2026

References

access.redhat.com / errata/RHSA-2026:19752
access.redhat.com / errata/RHSA-2026:23231
access.redhat.com / errata/RHSA-2026:24369
access.redhat.com / security/cve/CVE-2026-33278
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-33278.json
nlnetlabs.nl / downloads/unbound/CVE-2026-33278.txt
MitigationVendor Advisory