CVE-2026-55991
published 2026-07-22CVE-2026-55991: In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
0.36%
28.0th percentile
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is caused by an erroneous error value passed to libngtcp2. When 'ngtcp2_conn_writev_stream()' returns 'NGTCP2_ERR_STREAM_DATA_BLOCKED', Unbound continues to call 'ngtcp2_ccerr_set_application_error()' with a '-1' error value. The 'int' literal '-1' is implicitly converted to the function's 'uint64_t error_code' parameter as '0xFFFFFFFFFFFFFFFF'. The follow-on 'ngtcp2_conn_write_connection_close()' serialises that value as a QUIC variable-length integer; because '2^64-1' exceeds the 62-bit varint ceiling, 'ngtcp2_put_uvarintlen()' fails 'assert(n < 4611686018427387904ULL)' and the whole resolver process aborts. A remote, unauthenticated DoQ client can trigger this deterministically with a single QUIC connection by advertising 'initial_max_stream_data_bidi_local = 1' in its transport parameters and sending one DoQ query without ever reading the stream.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nlnet_labs | unbound | >= 1.22.0 < 1.25.2 | 1.25.2 |
| nlnetlabs | unbound | — | — |
| nlnetlabs | unbound | >= 1.22.0 < 1.25.2 | 1.25.2 |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection
vendor_redhat·2026-07-22·CVSS 5.9
CVE-2026-55991 [MEDIUM] CWE-190 unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection
unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection
A flaw was found in Unbound. A remote, unauthenticated client can exploit this vulnerability by sending a specially crafted DNS-over-QUIC (DoQ) connection and a single DNS query. This can trigger an assertion failure in the libngtcp2 library, leading to the termination of the entire Unbound process. This results in a Denial of Service (DoS), making the DNS resolver unavailable.
Statement: This Moderate flaw in Unbound allows a remote, unauthenticated client to cause a denial of service. By sending a specially crafted DNS-over-QUIC (DoQ) connection and a single DNS query, an attacker can terminate the Unbound process, making the DNS resolver unavailable. This vulnerability affects Unbound instances configured to supp
VulDB
NLnet Labs Unbound up to 1.25.1 Varint serialization ngtcp2_put_uvarintlen error_code input validation (WID-SEC-2026-2492)
vuldb·2026-09-11·CVSS 5.9
CVE-2026-55991 [MEDIUM] NLnet Labs Unbound up to 1.25.1 Varint serialization ngtcp2_put_uvarintlen error_code input validation (WID-SEC-2026-2492)
A vulnerability marked as critical has been reported in NLnet Labs Unbound up to 1.25.1. This affects the function ngtcp2_put_uvarintlen of the component Varint serialization. This manipulation of the argument error_code causes improper input validation.
This vulnerability is handled as CVE-2026-55991. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process usi
ghsa_unreviewed·2026-07-22
CVE-2026-55991 [MEDIUM] CWE-195 In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process usi
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is caused by an erroneous error value passed to libngtcp2. When 'ngtcp2_conn_writev_stream()' returns 'NGTCP2_ERR_STREAM_DATA_BLOCKED', Unbound continues to call 'ngtcp2_ccerr_set_application_error()' with a '-1' error value. The 'int' literal '-1' is implicitly converted to the function's 'uint64_t error_code' parameter as '0xFFFFFFFFFFFFFFFF'. The follow-on 'ngtcp2_conn_write_connection_close()' serialises that value as a QUIC variable-length integer; because '2^64-1' exceeds the 62-bit varint ceiling, 'ngtcp2_put_uvar
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55991 unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection [fedora-all]
bugzilla·2026-07-27·CVSS 5.9
CVE-2026-55991 [MEDIUM] CVE-2026-55991 unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection [fedora-all]
CVE-2026-55991 unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is caused by an erroneous error value passed to libngtcp2. When 'ngtcp2_conn_writev_stream()' returns 'NGTCP2_ERR_STREAM_DATA_BLOCKED', Unbound continues to call 'ngtcp2_ccerr_set_application_error()
Bugzilla
CVE-2026-55991 unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection
bugzilla·2026-07-22·CVSS 5.9
CVE-2026-55991 [MEDIUM] CVE-2026-55991 unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection
CVE-2026-55991 unbound: Unbound: Denial of Service via crafted DNS-over-QUIC connection
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is caused by an erroneous error value passed to libngtcp2. When 'ngtcp2_conn_writev_stream()' returns 'NGTCP2_ERR_STREAM_DATA_BLOCKED', Unbound continues to call 'ngtcp2_ccerr_set_application_error()' with a '-1' error value. The 'int' literal '-1' is implicitly converted to the function's 'uint64_t error_code' parameter as '0xFFFFFFFFFFFFFFFF'. The follow-on 'ngtcp2_conn_write_connection_close()' serialises that value as a QUIC vari
2026-07-22
Published