PT-2026-63367 · Libngtcp2+1 · Libngtcp2+1

·

CVE-2026-14586

·

Published

2026-07-22

·

Updated

2026-08-26

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.22.0 through 1.25.1
Description In DNS-over-QUIC (DoQ) environments, high concurrency and system pressure can trigger an assertion in the libngtcp2 library regarding monotonic timestamps. This occurs because Unbound uses realtime instead of the expected monotonic time when interfacing with libngtcp2, leading to server termination and a denial of service. This issue requires Unbound to be compiled with DoQ support using the --with-libngtcp2 flag and the quic-port to be configured for the listening interfaces.
Recommendations For versions 1.22.0 through 1.25.1, update the software to a version where this issue is resolved. As a temporary mitigation, avoid configuring the quic-port for listening interfaces or disable DNS-over-QUIC support.

Fix

DoS

Assertion Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92967
CVE-2026-14586
ECHO-E518-E2E7-E89C
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1

Affected Products

Unbound
Libngtcp2