Heap-based buffer overflow in Unbound - CVE-2026-40691
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to heap-based buffer overflow in the DNSCrypt packet reading and reply encryption procedure when processing a crafted DNSCrypt query over TCP. A remote attacker can send a specially crafted DNSCrypt query to cause a denial of service.
Only installations compiled with DNSCrypt support and configured with the dnscrypt feature enabled for listening interfaces are vulnerable.