EDNS Client Subnet Vulnerability in DNSdist by PowerDNS
CVE-2026-42004
3.7LOW
What is CVE-2026-42004?
A vulnerability in DNSdist allows attackers to send a specially crafted EDNS OPT record, bypassing DNS filtering rules. This manipulated record is then rewritten to appear valid when EDNS Client Subnet is inserted. As a consequence, the backend server receives EDNS options that were initially ignored by DNSdist, potentially exposing it to further exploits and compromised security.
Affected Version(s)
DNSdist 1.9.0 < 1.9.15
DNSdist 2.0.0 < 2.0.7
