PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-41637 NLnet Labs CVE debrief

A vulnerability in Unbound 1.22.0-1.25.1 can cause DNS-over-QUIC (DoQ) queries to be improperly accounted for, leading to service degradation for new clients. This occurs when client-terminated DoQ queries are not properly counted, causing an inflation of waiting replies for in-flight resolution queries. Exploitation requires Unbound to be compiled with DoQ support and configured to listen on a QUIC port. The vulnerability has a low CVSS score of 3.7 and is considered a low-priority vulnerability due to the specific configurations and access requirements.

Vendor
NLnet Labs
Product
Unbound
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Users of Unbound 1.22.0-1.25.1 with DoQ support enabled should verify their configurations and consider updating to a patched version. This includes operators of Unbound installations with DoQ support enabled, as well as security teams and vulnerability management teams responsible for monitoring and mitigating vulnerabilities.

Technical summary

In Unbound 1.22.0-1.25.1, client-terminated DoQ queries are not properly accounted for, causing an inflation of waiting replies for in-flight resolution queries. This can lead to silent query drops for new clients. Exploitation requires access to multiple source IPs and bypassing the 'wait-limit' option. The vulnerability is caused by the improper counting of terminated DoQ queries, which inflates the number of waiting replies for in-flight queries. This results in degradation of resolution service for new clients.

Defensive priority

Low-priority vulnerability due to the requirement for specific configurations and access to multiple source IPs.

Recommended defensive actions

  • Verify Unbound configurations for DoQ support and QUIC port usage.
  • Consider updating to a patched version of Unbound.
  • Monitor for unusual query patterns and implement compensating controls.
  • Review official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-07-22T14:17:18.560Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. There is limited information available about the vulnerability, and defenders should verify the official CVE record and NVD entry for the latest information. The vulnerability affects Unbound 1.22.0-1.25.1 with DoQ support enabled. Evidence of exploitation is not currently available, but defenders should monitor for unusual query patterns.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T14:17:18.560Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.