Input validation error in Unbound - CVE-2026-32665
Published: July 23, 2026
Unbound
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service for new DoQ clients.
The vulnerability exists due to improper input validation in the downstream DNS-over-QUIC implementation when processing client-provided stream length values on new QUIC connections. A remote attacker can send specially crafted QUIC streams with large declared lengths to cause a denial of service for new DoQ clients.
The issue affects the first two bidirectional streams on a new QUIC connection and requires Unbound to be built with DoQ support and configured to listen on a quic-port.