CVE-2026-24029

MEDIUM

DNS over HTTPS ACL bypass

Title source: cna
STIX 2.1

Description

When the early_acl_drop (earlyACLDrop in Lua) option is disabled (default is enabled) on a DNS over HTTPs frontend using the nghttp2 provider, the ACL check is skipped, allowing all clients to send DoH queries regardless of the configured ACL.

Scores

CVSS v3 6.5
EPSS 0.0000
EPSS Percentile 0.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
PowerDNS/DNSdist 1.9.0 - 1.9.12
powerdns/dnsdist 1.9.0 - 1.9.12
PowerDNS/DNSdist 2.0.0 - 2.0.3
Published Mar 31, 2026
Tracked Since Mar 31, 2026