CVE-2026-14586 - Medium Severity Vulnerability
Vulnerable Libraries - src4.0.4, src4.0.4, src4.0.4, src4.0.4
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (4)
/contrib/unbound/util/netevent.c
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (4)
/contrib/unbound/util/netevent.c
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (4)
/contrib/unbound/util/netevent.c
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (4)
/contrib/unbound/util/netevent.c
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
Found in HEAD commit: 816463d989cc5839c1cca2efb5bf2503408507fb
Found in base branches: stable/4.0, master
Vulnerability Details
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.
Publish Date: 2026-07-22
URL: CVE-2026-14586
CVSS 3 Score Details (5.9)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-07-22
Fix Resolution: https://github.com/NLnetLabs/unbound.git - release-1.25.2
Step up your Open Source Security Game with Mend here
CVE-2026-14586 - Medium Severity Vulnerability
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Found in HEAD commit: 816463d989cc5839c1cca2efb5bf2503408507fb
Found in base branches: stable/4.0, master
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.
Publish Date: 2026-07-22
URL: CVE-2026-14586
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-07-22
Fix Resolution: https://github.com/NLnetLabs/unbound.git - release-1.25.2
Step up your Open Source Security Game with Mend here