Resource exhaustion in Unbound - CVE-2026-41637
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource accounting in the DNS-over-QUIC query handling component when processing queries that are terminated by QUIC control frames. A remote attacker can send DNS-over-QUIC queries for names that require resolution and immediately terminate them to cause a denial of service.
Only deployments built with DNS-over-QUIC support and configured to listen on a QUIC port are vulnerable. Exploitation additionally requires access to multiple source IP addresses to bypass the default wait-limit setting.