OCTOBER 1, 2026
Live Feed
Back to database
Case File

CVE-2026-82720

MEDIUM · CVSS 5.9 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-16 · Last synced 2026-10-01

CyberRota Analysis

AI-Generated

Unbound versions 1.12.0 through 1.26.0, when compiled with DNS-over-HTTPs support, are vulnerable to a use-after-free issue that can occur during specific failure scenarios, such as RPZ drops or heavy traffic. Although the impact is somewhat limited, a successful exploitation can lead to denial of service through process termination by a hardened allocator. Organizations utilizing these versions with DNS-over-HTTPs should prioritize patching to mitigate potential disruptions.

CVE
CVE-2026-82720
Severity
MEDIUM
CVSS
5.9
EPSS
0.38%

Original NVD Description

NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If the prerequisites are satisfied (possible RPZ drop or heavy client traffic), a malicious actor can trigger the vulnerability with a single DoH connection and the appropriate traffic. Impact is limited as the reads are not user controlled and the use-after-free leads to early returns. However, a hardened allocator can catch the use-after-free and controllably terminate the process resulting to denial of service.

Related CVEs

Other vulnerabilities affecting the same vendor(s)