What is CVE-2026-41637?
In NLnet Labs Unbound versions 1.22.0 through 1.25.1, client-terminated DNS-over-QUIC queries are not properly accounted. This allows low-cost inflation of the waiting reply count for in-flight resolution queries, leading to degradation of the resolution service. It is recommended to upgrade to the latest stable release.
Azərbaycanca: NLnet Labs Unbound-un 1.22.0-dən 1.25.1-ə qədər versiyalarında client tərəfindən dayandırılmış DNS-over-QUIC sorğuları düzgün hesablanmır. Bu, gözləyən cavab sayının aşağı xərclə şişirdilməsinə səbəb olaraq DNS həll xidmətinin performansını azaldır. Təsirə məruz qalan versiyaları ən son stabil buraxılışa yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: NLnet Labs
FAQ2
Which NLnet Labs Unbound versions are affected by CVE-2026-41637?
NLnet Labs Unbound versions 1.22.0 through 1.25.1 are affected by this vulnerability.
How does CVE-2026-41637 affect the DNS service?
Improper accounting of client-terminated DNS-over-QUIC queries allows low-cost inflation of the waiting reply count, leading to degradation of the resolution service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.