CVE-2026-14586
Last modified
CVE-2026-14586 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time.
Description
In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in libngtcp2 about monotonic timestamps could trigger and result in server termination and thus denial of service. When interfacing with libngtcp2, for DNS-over-QUIC support in Unbound, it is expected to use monotonic time. Unbound was using realtime instead, and in DoQ environments with high concurrency and under pressure, an assert in libngtcp2 for the quic timestamp would trigger and terminate the server.This vulnerability needs Unbound to be compiled with DoQ support ('--with-libngtcp2') and the 'quic-port' to be configured for the listening interfaces.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| NLnet Labs | Unbound | >= 1.22.0, < 1.25.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-14586?
How severe is CVE-2026-14586?
How do I fix CVE-2026-14586?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14561The Authora : Easy login with mobile number WordPress plugin…6.5
- CVE-2026-14568The User Frontend: AI Powered Frontend Post Submission, User…6.5
- CVE-2026-1457An authenticated buffer handling flaw in TP-Link VIGI C385 V…8.8
- CVE-2026-14570Crypt::DSA versions before 1.22 for Perl draw the DSA signin…7.5
- CVE-2026-14574In Eclipse Theia versions 0.7.0 and up until including 1.73.…6.5
- CVE-2026-1458GitLab has remediated an issue in GitLab CE/EE affecting all…7.5
- CVE-2026-14587Neo4j's Bolt modern handshake decoder treats an overlong cap…5.5
- CVE-2026-1459A post-authentication command injection vulnerability in the…7.2
- CVE-2026-14592The WP Real IP-based Access Control WordPress plugin through…6.1
- CVE-2026-14596The DynamicKit for Elementor WordPress plugin before 1.0.3 d…8.8
- CVE-2026-1460A post-authentication command injection vulnerability in the…7.2
- CVE-2026-14602The Remote API WordPress plugin through 0.2 does not authent…9
Are you affected by CVE-2026-14586?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
