Client Termination Vulnerability in Unbound DNS by NLnet Labs
CVE-2026-41637
3.7LOW
What is CVE-2026-41637?
In NLnet Labs Unbound versions 1.22.0 to 1.25.1, a vulnerability exists where improperly accounted terminated DNS-over-QUIC (DoQ) queries can lead to an inflated number of waiting replies. This can degrade the DNS resolution service for new clients needing resolution on in-flight queries. Malicious actors can exploit this vulnerability by sending DoQ queries with the intention of terminating them using STOP_SENDING, RESET_STREAM, or CONNECTION_CLOSE QUIC frames. This issue requires Unbound to be compiled with DoQ support and properly configured to listen on QUIC ports. Additionally, an attacker needs access to multiple source IPs to bypass the default 'wait-limit' configured.
Affected Version(s)
Unbound 1.22.0 < 1.25.2
