CVE-2026-40208

LOW

PowerDNS DNSdist - Denial of Service via DoH3 Queries

Title source: rule
STIX 2.1

Description

An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.

Scores

CVSS v3 3.7
EPSS 0.0021
EPSS Percentile 10.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-705
Status published
Products (2)
PowerDNS/DNSdist 1.9.0 - 1.9.15
PowerDNS/DNSdist 2.0.0 - 2.0.7
Published Jun 25, 2026
Tracked Since Jun 25, 2026