Client Termination Vulnerability in Unbound DNS by NLnet Labs
CVE-2026-41637

3.7LOW

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-41637?

In NLnet Labs Unbound versions 1.22.0 to 1.25.1, a vulnerability exists where improperly accounted terminated DNS-over-QUIC (DoQ) queries can lead to an inflated number of waiting replies. This can degrade the DNS resolution service for new clients needing resolution on in-flight queries. Malicious actors can exploit this vulnerability by sending DoQ queries with the intention of terminating them using STOP_SENDING, RESET_STREAM, or CONNECTION_CLOSE QUIC frames. This issue requires Unbound to be compiled with DoQ support and properly configured to listen on QUIC ports. Additionally, an attacker needs access to multiple source IPs to bypass the default 'wait-limit' configured.

Affected Version(s)

Unbound 1.22.0 < 1.25.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.