What is CVE-2026-32665?
In NLnet Labs Unbound versions 1.22.0 through 1.25.1, when downstream DNS-over-QUIC (DoQ) is enabled, the first two bidirectional streams on a new QUIC connection bypass the 'quic-size' gate, leading to large buffer allocations. This could result in memory exhaustion vulnerabilities; disabling DoQ or updating to the latest version is recommended for affected systems.
Azərbaycanca: NLnet Labs Unbound-un 1.22.0-dən 1.25.1-ə qədər versiyalarında, downstream DNS-over-QUIC (DoQ) aktiv olduqda, yeni QUIC bağlantısında ilk iki bidirectional stream 'quic-size' limitini keçərək böyük bufer ayrılmasına səbəb olur. Bu, yaddaş istehlakı ilə bağlı zəifliklərə yol aça bilər; təsirlənən sistemlərdə DoQ-ni söndürmək və ya ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: NLnet Labs
FAQ2
Which versions of Unbound are affected by CVE-2026-32665?
This vulnerability affects NLnet Labs Unbound versions 1.22.0 through 1.25.1.
Is there a mitigation available for CVE-2026-32665?
Yes, it is recommended to disable downstream DNS-over-QUIC (DoQ) on affected systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.