Type conversion in Unbound - CVE-2026-55991
Published: July 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper type conversion in libngtcp2 error handling in the DNS-over-QUIC handling path when processing a DNS-over-QUIC connection and query. A remote attacker can send a specially crafted DNS-over-QUIC connection and query to cause a denial of service.
Exploitation requires assertions to be enabled and can be triggered by advertising an initial_max_stream_data_bidi_local value of 1 and sending a query without reading the stream.
Affected software
Fedora
unbound
How to mitigate CVE-2026-55991
unbound - update to 1.25.2-1.fc43