PT-2026-63372 · Nlnet · Unbound

·

CVE-2026-41637

·

Published

2026-07-22

·

Updated

2026-08-26

CVSS v3.1

3.7

Low

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions NLnet Labs Unbound versions 1.22.0 through 1.25.1
Description Client terminated DNS-over-QUIC (DoQ) queries are not accounted for properly, leading to an inflation of the waiting number of replies for in-flight resolution queries. This causes a degradation of resolution services for new clients. An attacker can trigger this by issuing DoQ queries and immediately terminating them using STOP SENDING, RESET STREAM, or CONNECTION CLOSE QUIC frames. Once the maximum limit is reached, new queries for in-flight resolutions are silently dropped. This issue requires the software to be compiled with DoQ support via --with-libngtcp2 and the quic-port to be configured. Additionally, the attacker must use multiple source IPs to bypass the wait-limit option.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Missing Release of Resource after Effective Lifetime

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92985
CVE-2026-41637
ECHO-DE58-3B9A-5F04
OPENSUSE-SU-2026:11380-1
OPENSUSE-SU-2026:21550-1
RHSA-2026:43588
SUSE-SU-2026:23050-1
SUSE-SU-2026:23215-1
SUSE-SU-2026:23226-1
SUSE-SU-2026:23349-1
SUSE-SU-2026:23360-1

Affected Products

Unbound