New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
CVE-2026-33278 (unbound RCE) affecting other services
in General
Hi!
From what I understand, the unbound RCE CVE-2026-33278 affects not only unbound itself, but everything using libunbound (which is such fun stuff like OpenDKIM and prosody), right?
If so, to quote a few posts from my last thread, "fuck".
Thanks & kind regards.

Comments
You should rename yourself to pechgoblin. Whenever you post something terrible has happened.
Like a fckin black cat. Holy shit man.
fuck
I promise it's just a phase. I used to bring joy and sunshine into peoples life.
(also, pechgoblin, I love it, thanks!)
Don't say anything against black cats. They might be too dumb to drink water without waterboarding themselves (at least ours is), but they are cute and cuddly (at least ours is
).
I wholeheartedly agree.
But, can anyone confirm that my suspicion is right? Or even better, tell me I'm dumb and OpenDKIM/Prosody are fine.
No SRE is going to have any moment to spare this year. 😇
Are you threatening them?
Looks like it affects cPanel
https://support.cpanel.net/hc/en-us/articles/40646746647703-Security-CVE-2026-33278-cpanel-unbound-1-25-1-Security-Release-May-21-2026
Who’s threatening cornholio?
Another weekend, another one. Fuck
There are likely few budget shared hosting providers that have never updated cPanel. Reputable providers will ensure updates are performed. But I am referring to those providers that were established as side hussles and then subsequently neglected.
Script kiddies going to have a field day.
I am curious to see how this will unfold, as Unbound is not only used in infrastructure as a resolver but is also frequently employed in hobby projects and home lab setups. Therefore, this may impact less experienced users more compared to the previous vulnerabilities.
its not real unless i have to reboot sorry
Bonus points if the fix that requires a reboot breaks grub.
Since this isn't fixed for a week now in Debian, I decided to patch it myself.
)
I have a deb for trixie if someone needs it, but its quite easy to build it yourself (which I'd recommend over trusting random pechgoblins on the internet