« Volver al listado

Powerdns

Powerdns Dnsdist: vulnerabilidades y CVE

Powerdns Dnsdist tiene 26 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE26
Últimos 12 meses19
Críticas1
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-42004Baja (3.7)0.22%—25 jun 2026
An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS…
CVE-2026-33602Alta (8.2)1.2%—22 abr 2026
A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value, triggering an out-of-bounds write leading to a denial of service.
CVE-2026-33599Alta (8.1)0.80%—22 abr 2026
A rogue backend can send a crafted SVCB response to a Discovery of Designated Resolvers request, when requested via either the autoUpgrade (Lua) option to newServer or auto_upgrade (YAML) settings. DDR upgrade is not…
CVE-2026-33598Crítica (9.1)2.8%—22 abr 2026
A cached crafted response can cause an out-of-bounds read if custom Lua code calls getDomainListByAddress() or getAddressListByDomain() on a packet cache.
CVE-2026-33597Alta (7.5)0.75%—22 abr 2026
PRSD detection denial of service
CVE-2026-33596Media (6.5)0.39%—22 abr 2026
A client might theoretically be able to cause a mismatch between queries sent to a backend and the received responses by sending a flood of perfectly timed queries that are routed to a TCP-only or DNS over TLS backend.
CVE-2026-33595Alta (7.5)0.80%—22 abr 2026
A client can trigger excessive memory allocation by generating a lot of errors responses over a single DoQ and DoH3 connection, as some resources were not properly released until the end of the connection.
CVE-2026-33594Alta (7.5)0.80%—22 abr 2026
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the…
CVE-2026-33593Alta (7.5)0.82%—22 abr 2026
A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.
CVE-2026-33254Alta (7.5)0.80%—22 abr 2026
An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default.
CVE-2026-33260Alta (7.5)1.1%—22 abr 2026
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
CVE-2026-33257Alta (7.5)1.1%—22 abr 2026
An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.
CVE-2026-27854Alta (7.5)1.3%—31 mar 2026
An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a…
CVE-2026-27853Alta (7.5)1.5%—31 mar 2026
An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. In some cases the…
CVE-2026-24030Alta (7.5)0.54%—31 mar 2026
An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory…
CVE-2026-24029Media (6.5)0.15%—31 mar 2026
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries…
CVE-2026-24028Alta (8.2)1.0%—31 mar 2026
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash,…
CVE-2026-0397Media (4.3)0.16%—31 mar 2026
When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running…
CVE-2026-0396Media (4.3)0.14%—31 mar 2026
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either…
CVE-2025-30187Baja (3.7)0.29%—18 sept 2025
In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an…
CVE-2025-30193Alta (7.5)0.61%—20 may 2025
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that…
CVE-2025-30194Alta (7.5)2.3%—29 abr 2025
When DNSdist is configured to provide DoH via the nghttp2 provider, an attacker can cause a denial of service by crafting a DoH exchange that triggers an illegal memory access (double-free) and crash of DNSdist, causing…
CVE-2024-25581Alta (7.5)1.1%—14 may 2024
When incoming DNS over HTTPS support is enabled using the nghttp2 provider, and queries are routed to a tcp-only or DNS over TLS backend, an attacker can trigger an assertion failure in DNSdist by sending a request for…
CVE-2018-14663Media (5.9)2.6%—26 nov 2018
An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data such that the addition of a record by dnsdist, for example an OPT record when adding EDNS…
CVE-2016-7069Alta (7.5)4.6%—11 sept 2018
An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain…
CVE-2017-7557Alta (8.8)0.84%—22 ago 2017
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application15
  2. T1499.004 Application or System Exploitation9
  3. T1499 Endpoint Denial of Service3
  4. T1059 Command and Scripting Interpreter2
  5. T1499.002 Service Exhaustion Flood2
  6. T1210 Exploitation of Remote Services1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Powerdns