Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.4

CVE-2026-82717: Unbound DNS server may expose data to attackers

CVE-2026-82717 · published 17 days ago
Summary

The Unbound DNS software used on Debian 13 systems can be manipulated so that an attacker can retrieve information they should not see. This could allow people to learn details about your network or intercept traffic. Update Unbound to the latest patched version provided for your Debian installation to close this gap.

What to do
  • Update unbound to version 1.17.1-2+deb12u4.aikido.5.
  • Update rootio-unbound to version 1.17.1-2+deb12u4.aikido.5.
  • Update unbound to version 1.22.0-2+deb13u3.aikido.4.
  • Update rootio-unbound to version 1.22.0-2+deb13u3.aikido.4.
  • Update debian unbound to version 1.26.1-0+deb13u1.
  • Update debian unbound to version 1.26.1-1.
  • Update unbound to version 1.25.2-r0.
  • Update unbound to version 1.25.2-r2.
  • Update nlnet labs unbound to version 1.26.1 or later.
  • Update nlnetlabs unbound to version 1.26.1 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:12 debian unbound All versions
Root:Debian:12 – unbound < 1.17.1-2+deb12u4.aikido.5
Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
Root:Debian:12 – rootio-unbound < 1.17.1-2+deb12u4.aikido.5
Fix: upgrade to 1.17.1-2+deb12u4.aikido.5
– nlnet labs unbound < 1.26.1
Ubuntu:Pro:14.04:LTS canonical unbound All versions
Root:Debian:13 – unbound < 1.22.0-2+deb13u3.aikido.4
Fix: upgrade to 1.22.0-2+deb13u3.aikido.4
Root:Debian:13 – rootio-unbound < 1.22.0-2+deb13u3.aikido.4
Fix: upgrade to 1.22.0-2+deb13u3.aikido.4
Debian:13 debian unbound < 1.26.1-0+deb13u1
Fix: upgrade to 1.26.1-0+deb13u1
Debian:14 debian unbound < 1.26.1-1
Fix: upgrade to 1.26.1-1
Alpine:v3.23 – unbound < 1.25.2-r0
Fix: upgrade to 1.25.2-r0
Alpine:v3.24 – unbound < 1.25.2-r2
Fix: upgrade to 1.25.2-r2
– nlnetlabs unbound < 1.26.1
cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:*
Original advisory text
CVE-2026-82717 in unbound - Patched by Root
Root has patched CVE-2026-82717 in the unbound package for Root:Debian:13. Multiple fixed versions available.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.4 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published23 Sep 2026
Updated9 Oct 2026
First seen16 Sep 2026
Track software like this
Free during beta