A vulnerability marked as critical has been reported in NLnet Labs Unbound up to 1.25.1. This affects the function
ngtcp2_put_uvarintlen of the component Varint serialization. This manipulation of the argument error_code causes improper input validation.
This vulnerability is handled as CVE-2026-55991. The attack can be initiated remotely. There is not any exploit available.