PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-40691 NLnet Labs CVE debrief

CVE-2026-40691 is a denial-of-service vulnerability in Unbound versions 1.9.0 through 1.25.1. The issue arises when a DNSCrypt query is received over TCP, and the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. This can lead to a crash of the resolver. The vulnerability requires Unbound to be compiled with DNSCrypt support and the 'dnscrypt:' clause to be configured and enabled for listening interfaces. Administrators and security teams responsible for Unbound DNS servers, especially those with DNSCrypt support enabled, should assess and mitigate this vulnerability to prevent potential denial-of-service attacks. The CVE record was published on 2026-07-22T14:17:18.437Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.

Vendor
NLnet Labs
Product
Unbound
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Administrators and security teams responsible for Unbound DNS servers, especially those with DNSCrypt support enabled, should assess and mitigate this vulnerability to prevent potential denial-of-service attacks. This includes reviewing Unbound configurations, monitoring service availability, and applying vendor patches or updates as necessary.

Technical summary

CVE-2026-40691 is a denial-of-service vulnerability in Unbound versions 1.9.0 through 1.25.1. The issue arises when a DNSCrypt query is received over TCP, and the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. This can lead to a crash of the resolver. The vulnerability requires Unbound to be compiled with DNSCrypt support and the 'dnscrypt:' clause to be configured and enabled for listening interfaces. A single malicious encrypted query crashes the resolver and lead to denial of service.

Defensive priority

High priority due to potential for denial-of-service attacks

Recommended defensive actions

  • Verify Unbound version and DNSCrypt configuration
  • Limit exposure of Unbound to untrusted networks
  • Implement monitoring for Unbound service availability
  • Review and apply vendor patches or updates
  • Consider disabling DNSCrypt if not required
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Official CVE and NVD records confirm the vulnerability. Limited details available from the source item. Further verification needed to assess affected scope and potential impact. Evidence from CVE.org and NVD detail page for CVE-2026-40691 indicate a denial-of-service vulnerability in Unbound versions 1.9.0 through 1.25.1. The issue arises when a DNSCrypt query is received over TCP, and the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. This can lead to a crash of the resolver. The vulnerability requires Unbound to be compiled with DNSCrypt support and the 'dnscrypt:' clause to be configured and enabled for listening interfaces. Additional verification tasks are recommended to assess affected scope and potential impact.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:18.437Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.