DNS-over-QUIC Vulnerability in NLnet Labs Unbound Server
CVE-2026-14586

5.9MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-14586?

In NLnet Labs Unbound versions 1.22.0 through 1.25.1, a vulnerability exists specifically in DNS-over-QUIC environments operating under high concurrency. The issue arises due to the incorrect use of realtime timestamps instead of monotonic timestamps when interfacing with libngtcp2. Under pressure conditions, this can lead to an assertion failure within libngtcp2, triggering server termination and resulting in a denial of service. To be affected, Unbound must be compiled with DNS-over-QUIC support and configured properly on the specified 'quic-port'.

Affected Version(s)

Unbound 1.22.0 < 1.25.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kunta Chu (Tsinghua University)
Kaihua Wang (Tsinghua University)
Jianjun Chen (Tsinghua University)
.