SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-55991

MEDIUM · CVSS 5.9 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Unbound versions 1.22.0 through 1.25.1 are vulnerable to a denial-of-service attack, where a remote unauthenticated client can exploit a flaw in the DNS-over-QUIC implementation to crash the Unbound resolver process. This is achieved by sending a single DNS query over a QUIC connection, which triggers an assertion failure due to an erroneous error value. Organizations using affected versions of Unbound should prioritize patching to mitigate potential disruptions to their DNS services.

CVE
CVE-2026-55991
Severity
MEDIUM
CVSS
5.9
EPSS
0.24%

Original NVD Description

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, a remote unauthenticated client can trigger a libngtcp2 assertion (if compiled with assertions on) and terminate the entire Unbound process using a single DNS-over-QUIC (DoQ) connection and one normal DNS query. This is caused by an erroneous error value passed to libngtcp2. When 'ngtcp2_conn_writev_stream()' returns 'NGTCP2_ERR_STREAM_DATA_BLOCKED', Unbound continues to call 'ngtcp2_ccerr_set_application_error()' with a '-1' error value. The 'int' literal '-1' is implicitly converted to the function's 'uint64_t error_code' parameter as '0xFFFFFFFFFFFFFFFF'. The follow-on 'ngtcp2_conn_write_connection_close()' serialises that value as a QUIC variable-length integer; because '2^64-1' exceeds the 62-bit varint ceiling, 'ngtcp2_put_uvarintlen()' fails 'assert(n < 4611686018427387904ULL)' and the whole resolver process aborts. A remote, unauthenticated DoQ client can trigger this deterministically with a single QUIC connection by advertising 'initial_max_stream_data_bidi_local = 1' in its transport parameters and sending one DoQ query without ever reading the stream.

Related CVEs

Other vulnerabilities affecting the same vendor(s)