CVE-2026-41637 - Low Severity Vulnerability
Vulnerable Libraries - src4.0.4, src4.0.4, src4.0.4, src4.0.4, src4.0.4, src4.0.4
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (5)
/contrib/unbound/util/netevent.c
/contrib/unbound/services/mesh.h
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (5)
/contrib/unbound/util/netevent.c
/contrib/unbound/services/mesh.h
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (5)
/contrib/unbound/util/netevent.c
/contrib/unbound/services/mesh.h
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (5)
/contrib/unbound/util/netevent.c
/contrib/unbound/services/mesh.h
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (5)
/contrib/unbound/util/netevent.c
/contrib/unbound/services/mesh.h
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Vulnerable Source Files (5)
/contrib/unbound/util/netevent.c
/contrib/unbound/services/mesh.h
/contrib/unbound/util/netevent.h
/contrib/unbound/services/listen_dnsport.h
/contrib/unbound/services/listen_dnsport.c
Found in HEAD commit: 816463d989cc5839c1cca2efb5bf2503408507fb
Found in base branches: stable/4.0, master
Vulnerability Details
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already in-flight resolution queries. This results in degradation of resolution service for new clients for already in-flight queries. A malicious actor can exploit the vulnerability by issuing DoQ queries for query names that need resolution and proceeding on immediately terminating the query by one of STOP_SENDING/RESET_STREAM/CONNECTION_CLOSE QUIC frames. Those terminated DoQ queries are not properly counted for and keep inflating the number of waiting replies for in-flight queries. When the maximum is reached, it results in silent query drops for new clients needing resolution for already in-flight queries. This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces. Additionally, a malicious actor needs access to multiple source IPs to bypass the by-default configured 'wait-limit' option.
Publish Date: 2026-07-22
URL: CVE-2026-41637
CVSS 3 Score Details (3.7)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Release Date: 2026-07-22
Fix Resolution: https://github.com/NLnetLabs/unbound.git - release-1.25.2
Step up your Open Source Security Game with Mend here
CVE-2026-41637 - Low Severity Vulnerability
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
src4.0.4
Library home page: https://github.com/MidnightBSD/src.git
Found in HEAD commit: 816463d989cc5839c1cca2efb5bf2503408507fb
Found in base branches: stable/4.0, master
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, client terminated DNS-over-QUIC (DoQ) queries are not accounted properly by Unbound resulting in low-cost inflation of the waiting number of replies for already in-flight resolution queries. This results in degradation of resolution service for new clients for already in-flight queries. A malicious actor can exploit the vulnerability by issuing DoQ queries for query names that need resolution and proceeding on immediately terminating the query by one of STOP_SENDING/RESET_STREAM/CONNECTION_CLOSE QUIC frames. Those terminated DoQ queries are not properly counted for and keep inflating the number of waiting replies for in-flight queries. When the maximum is reached, it results in silent query drops for new clients needing resolution for already in-flight queries. This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces. Additionally, a malicious actor needs access to multiple source IPs to bypass the by-default configured 'wait-limit' option.
Publish Date: 2026-07-22
URL: CVE-2026-41637
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: Low
For more information on CVSS3 Scores, click here.Type: Upgrade version
Release Date: 2026-07-22
Fix Resolution: https://github.com/NLnetLabs/unbound.git - release-1.25.2
Step up your Open Source Security Game with Mend here