CVE-2026-40208: Powerdns Dnsdist
Low severity, CVSS 3.7. EPSS: 0.4% chance of exploitation in the next 30 days.
An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.
Affected products
- Powerdns Dnsdist: from 1.9.0, before 1.9.15 (fixed in 1.9.15); from 2.0.0, before 2.0.7 (fixed in 2.0.7)
Published 2026-06-25. Last modified 2026-06-25.