Buffer Overflow Vulnerability in Unbound DNS Resolver by NLnet Labs
CVE-2026-40691

7.5HIGH

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-40691?

In certain versions of the Unbound DNS resolver, a buffer overflow vulnerability exists that affects processing DNSCrypt queries over TCP. When handling queries that return replies exceeding 65504 bytes, the system incorrectly manages buffer sizes, leading to potential crashes of the resolver. This flaw specifically requires Unbound to be compiled with DNSCrypt support and configured properly. If exploited, it could result in a denial of service, disrupting DNS resolution for users.

Affected Version(s)

Unbound 1.9.0 < 1.25.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
Trung Nguyen (@everping, CyStack)
.