unbound CVE-2026-81642 possible RCE

Author: SYNLINQCreated Sep 17, 2026Updated Sep 18, 2026
Labelsenhancement

Summary

Hello,

CVE-2026-81642 was published for unbound and allows potential remote code execution. We should update accordingly. However, there is currently no patched release in the alpine packages. A quick workaround would be to disable the dnssec validator module (https://nlnetlabs.nl/documentation/unbound/howto-turnoff-dnssec/) or alternatively compile the unbound from patched source.

Motivation

Keep mailcow secure

Additional context

No response

Source: mailcow/mailcow-dockerized