Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.4
CVE-2026-82717: Unbound DNS server may expose data to attackers
CVE-2026-82717 · published 17 days ago
Summary
The Unbound DNS software used on Debian 13 systems can be manipulated so that an attacker can retrieve information they should not see. This could allow people to learn details about your network or intercept traffic. Update Unbound to the latest patched version provided for your Debian installation to close this gap.
What to do
- Update unbound to version 1.17.1-2+deb12u4.aikido.5.
- Update rootio-unbound to version 1.17.1-2+deb12u4.aikido.5.
- Update unbound to version 1.22.0-2+deb13u3.aikido.4.
- Update rootio-unbound to version 1.22.0-2+deb13u3.aikido.4.
- Update debian unbound to version 1.26.1-0+deb13u1.
- Update debian unbound to version 1.26.1-1.
- Update unbound to version 1.25.2-r0.
- Update unbound to version 1.25.2-r2.
- Update nlnet labs unbound to version 1.26.1 or later.
- Update nlnetlabs unbound to version 1.26.1 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:12 | debian | unbound | All versions |
| Root:Debian:12 | – | unbound |
< 1.17.1-2+deb12u4.aikido.5 Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
|
| Root:Debian:12 | – | rootio-unbound |
< 1.17.1-2+deb12u4.aikido.5 Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
|
| – | nlnet labs | unbound | < 1.26.1 |
| Ubuntu:Pro:14.04:LTS | canonical | unbound | All versions |
| Root:Debian:13 | – | unbound |
< 1.22.0-2+deb13u3.aikido.4 Fix: upgrade to 1.22.0-2+deb13u3.aikido.4
|
| Root:Debian:13 | – | rootio-unbound |
< 1.22.0-2+deb13u3.aikido.4 Fix: upgrade to 1.22.0-2+deb13u3.aikido.4
|
| Debian:13 | debian | unbound |
< 1.26.1-0+deb13u1 Fix: upgrade to 1.26.1-0+deb13u1
|
| Debian:14 | debian | unbound |
< 1.26.1-1 Fix: upgrade to 1.26.1-1
|
| Alpine:v3.23 | – | unbound |
< 1.25.2-r0 Fix: upgrade to 1.25.2-r0
|
| Alpine:v3.24 | – | unbound |
< 1.25.2-r2 Fix: upgrade to 1.25.2-r2
|
| – | nlnetlabs | unbound |
< 1.26.1 cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:* |
Original advisory text
CVE-2026-82717 in unbound - Patched by Root
Root has patched CVE-2026-82717 in the unbound package for Root:Debian:13. Multiple fixed versions available.
References
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-82717.txt Patch Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2026-82717 Vendor Advisory
- https://security.alpinelinux.org/vuln/CVE-2026-82717 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-82717 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-82717 Third Party Advisory
- https://nlnetlabs.nl/downloads/unbound/CVE-2026-82717.txt Third Party Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published23 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Sources
CVE-2026-82717 · NVD
CVE-2026-82717 · MITRE
DEBIAN-CVE-2026-82717 · OSV
UBUNTU-CVE-2026-82717 · OSV
ALPINE-CVE-2026-82717 · OSV
CVE-2026-82717 · OSV
Track software like this
Free during beta