CVE-2026-32665
published 2026-07-22CVE-2026-32665: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.29%
21.3th percentile
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has been received from the initial streams. As a result, a remote client can make Unbound exceed the configured 'quic-size' limit with low-cost input. Using only one connection and two streams, each sending a declared 65535-byte length prefix and then holding the streams open, a client can already trivially make Unbound roughly allocate double that amount. This is a remote availability issue / memory-accounting bypass in the downstream DoQ implementation that leads to denial of service for new DoQ clients. This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.22.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | >= 1.22.0 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per
ghsa_unreviewed·2026-07-22
CVE-2026-32665 [HIGH] CWE-1284 In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection (stream_id 0 and 4) bypass the per-stream 'quic-size' gate entirely, and large input buffers are allocated later, after only the 2-byte length prefix has been received from the initial streams. As a result, a remote client can make Unbound exceed the configured 'quic-size' limit with low-cost input. Using only one connection and two streams, each sending a declared 65535-byte length prefix and then holding the streams open, a client can already trivially make Unbound roughly allocate double that amount. This is a remote availability issue / memory-accounting bypass in the downstream DoQ implementation that leads to denial of s
Red Hat
unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length
vendor_redhat·2026-07-22·CVSS 7.5
CVE-2026-32665 [HIGH] CWE-770 unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length
unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length
A flaw was found in Unbound when DNS-over-QUIC (DoQ) is enabled. An attacker could exploit improper validation of client-provided data length, leading to excessive memory allocation. This can cause the system to exceed its configured memory limits for QUIC connections, resulting in a Denial of Service (DoS) for new DoQ clients.
Statement: This Important flaw in Unbound, when configured for DNS-over-QUIC (DoQ), can lead to a denial of service for new DoQ clients. An attacker can exploit improper validation of client-provided data length, causing excessive memory allocation and exceeding configured limits. This impacts the availability of the DNS resolver for DoQ connections.
Mitigation: To mitigate
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-32665 unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length [fedora-all]
bugzilla·2026-07-27·CVSS 7.5
CVE-2026-32665 [HIGH] CVE-2026-32665 unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length [fedora-all]
CVE-2026-32665 unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When downstream DNS-over-QUIC (DoQ) is enabled, Unbound documents the 'quic-size' configuration option as the maximum number of bytes for all QUIC buffers and data combined, and states that new connections or streams should be refused/reset once the limit is exceeded. However, an improper validation of the client provided length could allow over allocating memory and trivially exceeding the configured budget for future DoQ connections leading to denia
Bugzilla
CVE-2026-32665 unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length
bugzilla·2026-07-20·CVSS 7.5
CVE-2026-32665 [HIGH] CVE-2026-32665 unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length
CVE-2026-32665 unbound: Unbound: Denial of Service via improper validation of DNS-over-QUIC client length
When downstream DNS-over-QUIC (DoQ) is enabled, Unbound documents the 'quic-size' configuration option as the maximum number of bytes for all QUIC buffers and data combined, and states that new connections or streams should be refused/reset once the limit is exceeded. However, an improper validation of the client provided length could allow over allocating memory and trivially exceeding the configured budget for future DoQ connections leading to denial of service for new DoQ clients.
2026-07-22
Published