CVE-2026-24030
CVE-2026-24030 is a medium-severity vulnerability in Powerdns Dnsdist with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-789.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- EPSS exploit prediction: 1% (43rd percentile)
- Actively exploited: Not listed in CISA KEV
- EU (EUVD) id: EUVD-2026-17405
- Weakness: CWE-789
- Affected product: Powerdns Dnsdist
- Published:
- Last modified:
Description
An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually results in an exception and the QUIC connection is properly closed, but in some cases the system might enter an out-of-memory state instead and terminate the process.
Frequently asked questions
- What is CVE-2026-24030?
- An attacker might be able to trick DNSdist into allocating too much memory while processing DNS over QUIC or DNS over HTTP/3 payloads, resulting in a denial of service. In setups with a large quantity of memory available this usually results in an exception and the QUIC connection is properly closed, but in some cases the system might enter an out-of-memory state instead and terminate the process.
- How severe is CVE-2026-24030?
- CVE-2026-24030 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity none, and availability low.
- Is CVE-2026-24030 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (43rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-24030?
- CVE-2026-24030 affects Powerdns Dnsdist. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2026-24030?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- Does CVE-2026-24030 have an EU (EUVD) identifier?
- Yes. CVE-2026-24030 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2026-17405.
- When was CVE-2026-24030 published?
- CVE-2026-24030 was published on 2026-03-31 and last updated on 2026-07-25.
References
Affected products (1)
- cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*
More vulnerabilities in Powerdns Dnsdist
- CVE-2017-7557 — High (CVSS 8.8): dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
- CVE-2026-33593 — High (CVSS 7.5): A client can trigger a divide by zero error leading to crash by sending a crafted DNSCrypt query.
- CVE-2026-33602 — Medium (CVSS 6.5): A rogue backend can send a crafted UDP response with a query ID off by one related to the maximum configured value,…
- CVE-2026-24029 — Medium (CVSS 6.5): When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend…
- CVE-2026-27853 — Medium (CVSS 5.9): An attacker might be able to trigger an out-of-bounds write by sending crafted DNS responses to a DNSdist using the…
- CVE-2018-14663 — Medium (CVSS 5.9): An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing…
All CVEs affecting Powerdns Dnsdist →
Other CWE-789 vulnerabilities
- CVE-2021-34869 — High (CVSS 8.8): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop…
- CVE-2021-34868 — High (CVSS 8.8): This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop…
- CVE-2026-69219 — High (CVSS 8.7): The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes.…
- CVE-2026-58067 — High (CVSS 8.7): A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause…
- CVE-2026-14682 — High (CVSS 8.7): In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This…
- CVE-2026-12852 — High (CVSS 8.7): In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.