Back to overview

CVE-2026-14586

MEDIUM
5.9
CVSS 3.1
Description
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.

Metadata

CVE ID
CVE-2026-14586
State
PUBLISHED
Assigner
NLnet Labs
Reserved
2026-07-03 11:59 UTC
Published
2026-07-22 13:03 UTC
Last updated
2026-07-22 14:33 UTC
Primary CWE
CWE-617
CWE-617: Reachable Assertion
Vendor / Product
NLnet Labs / Unbound
Sources
cve.org  ·  NVD

Severity & Metrics

5.9 MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (1)
VendorProductPlatformVersions
NLnet Labs Unbound 1.22.0 < 1.25.2
Weakness (CWE)
CWESourceDescription
CWE-617 cna CWE-617: Reachable Assertion
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.9 MEDIUM 3.1 cna CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Back to overview