Remote Code Execution Vulnerability in NLnet Labs Unbound DNS Resolver
CVE-2026-55991
5.9MEDIUM
What is CVE-2026-55991?
A vulnerability exists in NLnet Labs Unbound versions 1.22.0 to 1.25.1 that allows a remote, unauthenticated client to exploit a flaw in the processing of DNS-over-QUIC (DoQ) connections. By sending a crafted DNS query over a single QUIC connection, the attacker can trigger an assertion failure in the libngtcp2 library, causing the Unbound resolver process to terminate unexpectedly. This issue arises from an erroneous error value being passed during the handling of stream data, which leads to a fatal error condition and crash of the resolver. This vulnerability highlights the critical need for users to ensure their Unbound installations are updated to mitigate potential exploitation.
Affected Version(s)
Unbound 1.22.0 < 1.25.2
