Search CVE reports


Toggle filters

1 – 10 of 16 results


CVE-2026-27854

Medium priority
Needs evaluation

An attacker might be able to trigger a use-after-free by sending crafted DNS queries to a DNSdist using the DNSQuestion:getEDNSOptions method in custom Lua code. In some cases DNSQuestion:getEDNSOptions might refer to a version of...

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-27853

Medium priority
Needs evaluation

An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the DNSQuestion:changeName or DNSResponse:changeName methods in custom Lua code. In some cases the rewritten packet...

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-24030

Medium priority
Needs evaluation

An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available...

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-24029

Medium priority
Needs evaluation

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the...

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-24028

Medium priority
Needs evaluation

An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might trigger a crash, leading to a...

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0397

Medium priority
Needs evaluation

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration...

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2026-0396

Medium priority
Needs evaluation

An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via...

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Needs evaluation Needs evaluation Needs evaluation Needs evaluation
Show less packages

CVE-2025-30187

Medium priority
Fixed

In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded...

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Not affected Not affected Not affected Not affected
Show less packages

CVE-2025-8671

Medium priority

Some fixes available 2 of 23

A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to...

5 affected packages

h2o, haproxy, lighttpd, varnish, dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
h2o Needs evaluation Needs evaluation Needs evaluation Needs evaluation
haproxy Not affected Not affected Not affected Not affected
lighttpd Needs evaluation Needs evaluation Needs evaluation Needs evaluation
varnish Needs evaluation Needs evaluation Needs evaluation Needs evaluation
dnsdist Fixed Not affected Not affected Not affected
Show less packages

CVE-2025-30193

Medium priority

Some fixes available 2 of 4

In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an...

1 affected package

dnsdist

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
dnsdist Fixed Fixed Not affected Not affected
Show less packages