VendorsPowerDNSdnsdistall versions
Vulnerabilities

PowerDNS Dnsdist

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2026-33598
Out-of-bounds read in cache inspection via Lua
Published 2026-04-22 · Analyzed
9.1EPSS 0.028
CVE-2017-7557
dnsdist version 1.1.0 is vulnerable to a flaw in authentication mechanism for REST API potentially allowing CSRF attack.
Published 2017-08-22 · Modified
8.8EPSS 0.008
CVE-2026-33602
Off-by-one access when processing crafted UDP responses
Published 2026-04-22 · Analyzed
8.2EPSS 0.012
CVE-2026-24028
Out-of-bounds read when parsing DNS packets via Lua
Published 2026-03-31 · Analyzed
8.2EPSS 0.010
CVE-2026-33599
Out-of-bounds read in service discovery
Published 2026-04-22 · Analyzed
8.1EPSS 0.008
CVE-2016-7069
An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an EDNS0 OPT record that has to be removed before forwarding the response to the initial client. On a 32-bit system, the pointer arithmetic used when parsing the received response to remove that record might trigger an undefined behavior leading to a crash.
Published 2018-09-11 · Modified
7.5EPSS 0.046
CVE-2026-27853
Out-of-bounds write when rewriting large DNS packets
Published 2026-03-31 · Analyzed
7.5EPSS 0.015
CVE-2026-27854
Use after free when parsing EDNS options in Lua
Published 2026-03-31 · Analyzed
7.5EPSS 0.013
CVE-2026-33257
Insufficient input validation of internal webserver
Published 2026-04-22 · Analyzed
7.5EPSS 0.011
CVE-2026-33260
Insufficient input validation of internal webserver
Published 2026-04-22 · Analyzed
7.5EPSS 0.011
CVE-2026-33593
Denial of service via crafted DNSCrypt query
Published 2026-04-22 · Analyzed
7.5EPSS 0.008
CVE-2026-33254
Resource exhaustion via DoQ/DoH3 connections
Published 2026-04-22 · Analyzed
7.5EPSS 0.008
CVE-2026-33594
Outgoing DoH excessive memory allocation
Published 2026-04-22 · Analyzed
7.5EPSS 0.008
CVE-2026-33595
DoQ/DoH3 excessive memory allocation
Published 2026-04-22 · Analyzed
7.5EPSS 0.008
CVE-2026-33597
PRSD detection denial of service
Published 2026-04-22 · Analyzed
7.5EPSS 0.008
CVE-2026-24030
Unbounded memory allocation for DoQ and DoH3
Published 2026-03-31 · Analyzed
7.5EPSS 0.005
CVE-2026-33596
TCP backend stream ID overflow
Published 2026-04-22 · Analyzed
6.5EPSS 0.004
CVE-2026-24029
DNS over HTTPS ACL bypass
Published 2026-03-31 · Analyzed
6.5EPSS 0.001
CVE-2018-14663
An issue has been found in PowerDNS DNSDist before 1.3.3 allowing a remote attacker to craft a DNS query with trailing data such that the addition of a record by dnsdist, for example an OPT record when adding EDNS Client Subnet, might result in the trailing data being smuggled to the backend as a valid record while not seen by dnsdist. This is an issue when dnsdist is deployed as a DNS Firewall and used to filter some records that should not be received by the backend. This issue occurs only when either the 'useClientSubnet' or the experimental 'addXPF' parameters are used when declaring a new backend.
Published 2018-11-26 · Modified
5.9EPSS 0.026
CVE-2026-0397
Information disclosure via CORS misconfiguration
Published 2026-03-31 · Analyzed
4.3EPSS 0.002
CVE-2026-0396
HTML injection in the web dashboard
Published 2026-03-31 · Analyzed
4.3EPSS 0.001