In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries, an attacker might be able to cause a denial of service by crafting a DoH exchange that triggers an unbounded I/O read loop, causing an unexpected consumption of CPU resources.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade dnsdist | Dec 5, 2025 | Sep 18, 2025 |
| Debian | — | Upgrade dnsdist | Jul 23, 2026 | Jul 23, 2026 |
| Freebsd | — | Upgrade dnsdist | Dec 10, 2025 | Sep 24, 2025 |
| Ubuntu | — | Upgrade dnsdist (Ubuntu Pro)Upgrade dnsdist | Feb 13, 2026 | Sep 18, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub