Home
MEDIUM: 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LDefault status
unaffected
1.9.0 (semver) before 1.9.13
affected
2.0.0 (semver) before 2.0.4
affected
Description
A client can trigger excessive memory allocation by generating a lot of queries that are routed to an overloaded DoH backend, causing queries to accumulate into a buffer that will not be released until the end of the connection.
Problem types
Allocation of Resources Without Limits or Throttling
Product status
1.9.0 (semver) before 1.9.13
2.0.0 (semver) before 2.0.4
Credits
Mehtab Zafar
References
www.dnsdist.org/...owerdns-advisory-for-dnsdist-2026-04.html