Echo: unbound: security update to 1.26.1

medium Tenable Self-Hosted Container Security Plugin ID 458310

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- NLnet Labs Unbound 1.12.0 up to and including 1.26.0 has a use-after-free vulnerability when compiled for
DNS-over-HTTPs support with '--with-libnghttp2'. During failure code paths (i.e., RPZ drop query, jostle
due to heavy traffic), a dropped DoH stream brings down the whole DoH session and does not account
properly for other DoH streams in the same session. This leads to use-after-free in those code paths. If
the prerequisites are satisfied (possible RPZ drop or heavy client traffic), a malicious actor can trigger
the vulnerability with a single DoH connection and the appropriate traffic. Impact is limited as the reads
are not user controlled and the use-after-free leads to early returns. However, a hardened allocator can
catch the use-after-free and controllably terminate the process resulting to denial of service.
(CVE-2026-82720)

Solution

Update the unbound library and its related packages to version 1.26.1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-82720

Plugin Details

Severity: Medium

ID: 458310

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.61

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2026-82720

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/16/2026

Vulnerability Publication Date: 9/16/2026

Reference Information

CVE: CVE-2026-82720

IAVA: 2026-A-1070