DoH3 Query Processing Delays in PowerDNS by PowerDNS
CVE-2026-40208

3.7LOW

Key Information:

Vendor

Powerdns

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-40208?

The vulnerability in PowerDNS allows an attacker to potentially disrupt the normal operation of DoH3 queries by sending GET requests containing invalid DATA frames. This misconfiguration can lead to significant delays in DNS query responses, affecting service availability and performance.

Affected Version(s)

DNSdist 1.9.0 < 1.9.15

DNSdist 2.0.0 < 2.0.7

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ylwango613
.