Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
1.9.0 (semver) before 1.9.13
affected
2.0.0 (semver) before 2.0.4
affected
Description
An attacker can create a large number of concurrent DoQ or DoH3 connections, causing unlimited memory allocation in DNSdist and leading to a denial of service. DOQ and DoH3 are disabled by default.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
1.9.0 (semver) before 1.9.13
2.0.0 (semver) before 2.0.4
Credits
Salvor Labs - https://salvor.fr
References
www.dnsdist.org/...owerdns-advisory-for-dnsdist-2026-04.html