PatchSiren cyber security CVE debrief
CVE-2026-40691 NLnet Labs CVE debrief
CVE-2026-40691 is a denial-of-service vulnerability in Unbound versions 1.9.0 through 1.25.1. The issue arises when a DNSCrypt query is received over TCP, and the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. This can lead to a crash of the resolver. The vulnerability requires Unbound to be compiled with DNSCrypt support and the 'dnscrypt:' clause to be configured and enabled for listening interfaces. Administrators and security teams responsible for Unbound DNS servers, especially those with DNSCrypt support enabled, should assess and mitigate this vulnerability to prevent potential denial-of-service attacks. The CVE record was published on 2026-07-22T14:17:18.437Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.
- Vendor
- NLnet Labs
- Product
- Unbound
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-22
- Original CVE updated
- 2026-07-22
- Advisory published
- 2026-07-22
- Advisory updated
- 2026-07-22
Who should care
Administrators and security teams responsible for Unbound DNS servers, especially those with DNSCrypt support enabled, should assess and mitigate this vulnerability to prevent potential denial-of-service attacks. This includes reviewing Unbound configurations, monitoring service availability, and applying vendor patches or updates as necessary.
Technical summary
CVE-2026-40691 is a denial-of-service vulnerability in Unbound versions 1.9.0 through 1.25.1. The issue arises when a DNSCrypt query is received over TCP, and the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. This can lead to a crash of the resolver. The vulnerability requires Unbound to be compiled with DNSCrypt support and the 'dnscrypt:' clause to be configured and enabled for listening interfaces. A single malicious encrypted query crashes the resolver and lead to denial of service.
Defensive priority
High priority due to potential for denial-of-service attacks
Recommended defensive actions
- Verify Unbound version and DNSCrypt configuration
- Limit exposure of Unbound to untrusted networks
- Implement monitoring for Unbound service availability
- Review and apply vendor patches or updates
- Consider disabling DNSCrypt if not required
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Official CVE and NVD records confirm the vulnerability. Limited details available from the source item. Further verification needed to assess affected scope and potential impact. Evidence from CVE.org and NVD detail page for CVE-2026-40691 indicate a denial-of-service vulnerability in Unbound versions 1.9.0 through 1.25.1. The issue arises when a DNSCrypt query is received over TCP, and the routine that encrypts the reply in place fails to bound the reply length against the destination buffer size. This can lead to a crash of the resolver. The vulnerability requires Unbound to be compiled with DNSCrypt support and the 'dnscrypt:' clause to be configured and enabled for listening interfaces. Additional verification tasks are recommended to assess affected scope and potential impact.
Official resources
-
CVE-2026-40691 CVE record
CVE.org
-
CVE-2026-40691 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:18.437Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.