DNS-over-QUIC Vulnerability in NLnet Labs Unbound Server
CVE-2026-14586
5.9MEDIUM
What is CVE-2026-14586?
In NLnet Labs Unbound versions 1.22.0 through 1.25.1, a vulnerability exists specifically in DNS-over-QUIC environments operating under high concurrency. The issue arises due to the incorrect use of realtime timestamps instead of monotonic timestamps when interfacing with libngtcp2. Under pressure conditions, this can lead to an assertion failure within libngtcp2, triggering server termination and resulting in a denial of service. To be affected, Unbound must be compiled with DNS-over-QUIC support and configured properly on the specified 'quic-port'.
Affected Version(s)
Unbound 1.22.0 < 1.25.2
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Kunta Chu (Tsinghua University)
Kaihua Wang (Tsinghua University)
Jianjun Chen (Tsinghua University)
