What is CVE-2026-14586?
In NLnet Labs Unbound versions 1.22.0 through 1.25.1, under high concurrency in DNS-over-QUIC environments, an assertion failure regarding monotonic timestamps in the libngtcp2 library can lead to server termination. This results in a denial of service (DoS). Affected systems should be updated to a patched version.
Azərbaycanca: NLnet Labs Unbound 1.22.0-1.25.1 versiyalarında, DNS-over-QUIC mühitlərində yüksək paralellik zamanı 'libngtcp2' kitabxanasındakı monoton zaman damğası təsdiqi uğursuz olaraq serverin dayanmasına səbəb olur. Nəticədə denial of service (DoS) yaranır. Təsirə məruz qalan sistemlərdə proqram təminatını yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: NLnet Labs
FAQ2
Which versions of NLnet Labs Unbound are affected by CVE-2026-14586?
This vulnerability affects NLnet Labs Unbound versions 1.22.0 through 1.25.1.
Under what conditions does CVE-2026-14586 cause a Denial of Service (DoS)?
This vulnerability causes a Denial of Service (DoS) when an assertion failure related to monotonic timestamps in the 'libngtcp2' library occurs under high concurrency in DNS-over-QUIC environments, leading to server termination.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.