Remote Code Execution Vulnerability in NLnet Labs Unbound DNS Resolver
CVE-2026-55991

5.9MEDIUM

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-55991?

A vulnerability exists in NLnet Labs Unbound versions 1.22.0 to 1.25.1 that allows a remote, unauthenticated client to exploit a flaw in the processing of DNS-over-QUIC (DoQ) connections. By sending a crafted DNS query over a single QUIC connection, the attacker can trigger an assertion failure in the libngtcp2 library, causing the Unbound resolver process to terminate unexpectedly. This issue arises from an erroneous error value being passed during the handling of stream data, which leads to a fatal error condition and crash of the resolver. This vulnerability highlights the critical need for users to ensure their Unbound installations are updated to mitigate potential exploitation.

Affected Version(s)

Unbound 1.22.0 < 1.25.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
Xuanchao Xie
.