CVE-2026-14586
published 2026-07-22CVE-2026-14586: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.27%
19.2th percentile
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.22.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and
ghsa_unreviewed·2026-07-22
CVE-2026-14586 [MEDIUM] CWE-617 In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.
Red Hat
unbound: libngtcp2: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments
vendor_redhat·2026-07-22·CVSS 5.9
CVE-2026-14586 [MEDIUM] CWE-617 unbound: libngtcp2: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments
unbound: libngtcp2: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments
A flaw was found in Unbound. Under heavy DNS-over-QUIC (DoQ) traffic, a timing discrepancy in Unbound’s libngtcp2 library can trigger an assertion failure. This causes the server to crash unexpectedly, resulting in a denial of service (DoS).
Statement: Moderate: This Unbound vulnerability, leading to a denial of service, is contingent on the resolver being compiled with DNS-over-QUIC (DoQ) support and having a `quic-port` configured. The flaw manifests under high concurrency and network pressure due to a timing discrepancy in the `libngtcp2` library. Red Hat deployments not utilizing DoQ or without the `quic-port` enabled are not affected.
Mitigation: Disable DNS-over-QUIC (DoQ) by removin
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-14586 unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments [fedora-all]
bugzilla·2026-07-24·CVSS 5.9
CVE-2026-14586 [MEDIUM] CVE-2026-14586 unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments [fedora-all]
CVE-2026-14586 unbound: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under
Bugzilla
CVE-2026-14586 unbound: libngtcp2: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments
bugzilla·2026-07-22·CVSS 5.9
CVE-2026-14586 [MEDIUM] CVE-2026-14586 unbound: libngtcp2: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments
CVE-2026-14586 unbound: libngtcp2: Unbound: Denial of Service via assertion failure in DNS-over-QUIC environments
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the
2026-07-22
Published