CVE-2026-0396
- EPSS 0.14%
- Veröffentlicht 31.03.2026 11:50:51
- Zuletzt bearbeitet 25.07.2026 10:10:00
An attacker might be able to inject HTML content into the internal web dashboard by sending crafted DNS queries to a DNSdist instance where domain-based dynamic rules have been enabled via either DynBlockRulesGroup:setSuffixMatchRule or DynBlockRules...
CVE-2025-59024
- EPSS 0.12%
- Veröffentlicht 09.02.2026 14:44:28
- Zuletzt bearbeitet 20.04.2026 15:11:15
Crafted delegations or IP fragments can poison cached delegations in Recursor.
CVE-2025-59023
- EPSS 0.27%
- Veröffentlicht 09.02.2026 14:44:19
- Zuletzt bearbeitet 20.04.2026 15:11:13
Crafted delegations or IP fragments can poison cached delegations in Recursor.
CVE-2026-24027
- EPSS 0.4%
- Veröffentlicht 09.02.2026 14:25:24
- Zuletzt bearbeitet 20.04.2026 14:55:39
Crafted zones can lead to increased incoming network traffic.
CVE-2026-0398
- EPSS 0.3%
- Veröffentlicht 09.02.2026 14:20:46
- Zuletzt bearbeitet 20.04.2026 14:55:46
Crafted zones can lead to increased resource usage and crafted CNAME chains can lead to cache poisoning in Recursor.
CVE-2025-59029
- EPSS 0.37%
- Veröffentlicht 09.12.2025 09:16:03
- Zuletzt bearbeitet 07.10.2026 20:10:01
An attacker can trigger an assertion failure by requesting crafted DNS records, waiting for them to be inserted into the records cache, then send a query with qtype set to ANY.
CVE-2025-59030
- EPSS 0.55%
- Veröffentlicht 09.12.2025 09:15:43
- Zuletzt bearbeitet 07.10.2026 20:10:01
An attacker can trigger the removal of cached records by sending a NOTIFY query over TCP.
CVE-2025-30187
- EPSS 0.29%
- Veröffentlicht 18.09.2025 09:21:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causi...
CVE-2025-30192
- EPSS 0.23%
- Veröffentlicht 21.07.2025 12:49:31
- Zuletzt bearbeitet 15.04.2026 00:35:42
An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining E...
CVE-2025-30193
- EPSS 0.61%
- Veröffentlicht 20.05.2025 11:17:17
- Zuletzt bearbeitet 15.04.2026 00:35:42
In some circumstances, when DNSdist is configured to allow an unlimited number of queries on a single, incoming TCP connection from a client, an attacker can cause a denial of service by crafting a TCP exchange that triggers an exhaustion of the stac...