CVE-2026-40209: Powerdns Dnsdist
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.
Affected products
- Powerdns Dnsdist: from 1.9.0, before 1.9.15 (fixed in 1.9.15); from 2.0.0, before 2.0.7 (fixed in 2.0.7)
Published 2026-06-25. Last modified 2026-06-25.