PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-41637 NLnet Labs CVE debrief

A vulnerability in Unbound 1.22.0-1.25.1 can cause DNS-over-QUIC (DoQ) queries to be improperly accounted for, leading to service degradation for new clients. This occurs when client-terminated DoQ queries are not properly counted, causing an inflation of waiting replies for in-flight resolution queries. Exploitation requires Unbound to be compiled with DoQ support and configured to listen on a QUIC port. The vulnerability has a low CVSS score of 3.7 and is considered a low-priority vulnerability due to the specific configurations and access requirements.

Vendor
NLnet Labs
Product
Unbound
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Users of Unbound 1.22.0-1.25.1 with DoQ support enabled should verify their configurations and consider updating to a patched version. This includes operators of Unbound installations with DoQ support enabled, as well as security teams and vulnerability management teams responsible for monitoring and mitigating vulnerabilities.

Technical summary

In Unbound 1.22.0-1.25.1, client-terminated DoQ queries are not properly accounted for, causing an inflation of waiting replies for in-flight resolution queries. This can lead to silent query drops for new clients. Exploitation requires access to multiple source IPs and bypassing the 'wait-limit' option. The vulnerability is caused by the improper counting of terminated DoQ queries, which inflates the number of waiting replies for in-flight queries. This results in degradation of resolution service for new clients.

Defensive priority

Low-priority vulnerability due to the requirement for specific configurations and access to multiple source IPs.

Recommended defensive actions

  • Verify Unbound configurations for DoQ support and QUIC port usage.
  • Consider updating to a patched version of Unbound.
  • Monitor for unusual query patterns and implement compensating controls.
  • Review official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-07-22T14:17:18.560Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. There is limited information available about the vulnerability, and defenders should verify the official CVE record and NVD entry for the latest information. The vulnerability affects Unbound 1.22.0-1.25.1 with DoQ support enabled. Evidence of exploitation is not currently available, but defenders should monitor for unusual query patterns.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-41637 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-41637

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-41637 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-41637

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.