CVE-2026-82720
Last modified
CVE-2026-82720 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If the prerequisites are satisfied (possible RPZ drop or heavy client traffic), a malicious actor can trigger the vulnerability with a single DoH connection and the appropriate traffic. Impact is limited as the reads are not user controlled and the use-after-free leads to early returns. However, a hardened allocator can catch the use-after-free and controllably terminate the process resulting to denial of service.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nlnetlabs | Unbound | >= 1.12.0, < 1.26.1 |
References
- https://www.nlnetlabs.nl/downloads/unbound/CVE-2026-82720.txtPatch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-82720?
How severe is CVE-2026-82720?
How do I fix CVE-2026-82720?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8271A vulnerability was identified in D-Link DNS-320 2.06B01. Th…7.2
- CVE-2026-82710Improper Neutralization of Escape, Meta, or Control Sequence…2.3
- CVE-2026-82712Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior ar…8.8
- CVE-2026-82716The Botslab G980H dash camera firmware includes sensitive co…4.6
- CVE-2026-82717In NLnet Labs Unbound up to and including 1.26.0, a vulnerab…9.8
- CVE-2026-8272A security flaw has been discovered in D-Link DNS-320 2.06B0…7.2
- CVE-2026-82722Allocation of Resources Without Limits or Throttling vulnera…8.3
- CVE-2026-82723Insertion of Sensitive Information into Log File vulnerabili…1.8
- CVE-2026-82724Incorrect Authorization vulnerability in ash-project ash_pho…7.6
- CVE-2026-82725Authorization Bypass Through User-Controlled Key vulnerabili…2.3
- CVE-2026-82726Permissive Regular Expression vulnerability in ash-project a…6.3
- CVE-2026-82727Generation of Error Message Containing Sensitive Information…2.3
Are you affected by CVE-2026-82720?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
