CVE-2026-24029: Powerdns Dnsdist

Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.

Affected products

  • Powerdns Dnsdist: from 1.9.0, before 1.9.12 (fixed in 1.9.12); from 2.0.0, before 2.0.3 (fixed in 2.0.3)

Published 2026-03-31. Last modified 2026-07-25.