CVE-2026-24029: Powerdns Dnsdist
Medium severity, CVSS 6.5. EPSS: 0.1% chance of exploitation in the next 30 days.
When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.
Affected products
- Powerdns Dnsdist: from 1.9.0, before 1.9.12 (fixed in 1.9.12); from 2.0.0, before 2.0.3 (fixed in 2.0.3)
Published 2026-03-31. Last modified 2026-07-25.