Input validation error in Unbound - CVE-2026-32665
Published: July 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service for new DoQ clients.
The vulnerability exists due to improper input validation in the downstream DNS-over-QUIC implementation when processing client-provided stream length values on new QUIC connections. A remote attacker can send specially crafted QUIC streams with large declared lengths to cause a denial of service for new DoQ clients.
The issue affects the first two bidirectional streams on a new QUIC connection and requires Unbound to be built with DoQ support and configured to listen on a quic-port.
Affected software
Fedora
unbound
How to mitigate CVE-2026-32665
unbound - update to 1.25.2-1.fc43